Technical Information
- [<HKLM>\SOFTWARE\Classes\MSProgramGroup\Shell\Open\Command] '' = '<SYSTEM32>\grpconv.exe %1'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'GrpConv' = 'grpconv -o'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Earthlink Protection Control Center' = '%PROGRAM_FILES%\EarthLink\elnk_pcc.exe /minimize'
- [<HKLM>\SYSTEM\ControlSet001\Services\GRTdiMon] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\GRFILTER] 'Start' = '00000000'
- [<HKLM>\SYSTEM\ControlSet001\Services\ADSService] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\CSS DVP] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\dvpapi] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\GRTdiMon] 'ImagePath' = 'System32\Drivers\GRTdiMon.sys'
- '%TEMP%\GLJ2.tmp' <SYSTEM32>\ASE.dll
- '%TEMP%\GLJ2.tmp' %PROGRAM_FILES%\EarthLink\PlayGifo.ocx
- '%TEMP%\GLJ2.tmp' <SYSTEM32>\AluriaReg.dll
- '%TEMP%\GLJ2.tmp' <SYSTEM32>\RICHTX32.OCX
- '%TEMP%\GLJ2.tmp' <SYSTEM32>\Msstdfmt.dll
- '%PROGRAM_FILES%\EarthLink\elnkserv.exe'
- '%PROGRAM_FILES%\EarthLink\elnk_pcc.exe'
- '%TEMP%\GLJ2.tmp' %PROGRAM_FILES%\EarthLink\wscapi.dll
- '%TEMP%\GLJ2.tmp' %PROGRAM_FILES%\EarthLink\HoverMenu.ocx
- '%TEMP%\GLJ2.tmp' %PROGRAM_FILES%\EarthLink\HoverImageButton.ocx
- '%TEMP%\GLJ2.tmp' <SYSTEM32>\MSINET.OCX
- '%CommonProgramFiles%\Command Software\fixdsknt.exe' -rrescue.dat
- '<SYSTEM32>\AuthFw.exe' /RegServer
- '%CommonProgramFiles%\Command Software\dvpapi.exe'
- '%CommonProgramFiles%\Command Software\dvpmgr.exe' -i
- '%CommonProgramFiles%\Command Software\dvpmgr.exe' -s
- '%TEMP%\GLJ2.tmp' <SYSTEM32>\MSCOMM32.OCX
- '%TEMP%\GLJ2.tmp' <SYSTEM32>\MSCOMCT2.OCX
- '%TEMP%\GLJ2.tmp' %CommonProgramFiles%\Command Software\odapi.dll
- '%TEMP%\GLJ2.tmp' <SYSTEM32>\MSCOMCTL.OCX
- '%TEMP%\GLJ2.tmp' <SYSTEM32>\COMDLG32.OCX
- '<SYSTEM32>\rundll32.exe' SETUPAPI.DLL,InstallHinfSection DefaultInstall 128 %PROGRAM_FILES%\EarthLink\ADSFilter.inf
- '<SYSTEM32>\msiexec.exe' -Embedding 764E0E85A7C424A57E179FDF232AC127
- '<SYSTEM32>\grpconv.exe' -o
- '<SYSTEM32>\runonce.exe' -r
- '<SYSTEM32>\msiexec.exe' /V
- '<SYSTEM32>\msiexec.exe' /i "%PROGRAM_FILES%\EarthLink\ins\avsdk.msi" /qn REBOOT=ReallySuppress
- '<SYSTEM32>\msiexec.exe' /i "%PROGRAM_FILES%\EarthLink\ins\AuthFW.msi" /qn REBOOT=ReallySuppress
- '<SYSTEM32>\msiexec.exe' -Embedding D0C0864DB2C1DBA8F1924729A1295FE1
- %PROGRAM_FILES%\EarthLink\temp.000
- %PROGRAM_FILES%\EarthLink\~GLH001f.TMP
- %PROGRAM_FILES%\EarthLink\~GLH0021.TMP
- <SYSTEM32>\~GLH0014.TMP
- <SYSTEM32>\~GLH001c.TMP
- %PROGRAM_FILES%\EarthLink\~GLH001d.TMP
- %PROGRAM_FILES%\EarthLink\~GLH0022.TMP
- <SYSTEM32>\~GLH0026.TMP
- %PROGRAM_FILES%\EarthLink\~GLH0027.TMP
- %PROGRAM_FILES%\EarthLink\~GLH0028.TMP
- %PROGRAM_FILES%\EarthLink\Dats\~GLH0023.TMP
- %PROGRAM_FILES%\EarthLink\Dats\~GLH0024.TMP
- <SYSTEM32>\~GLH0025.TMP
- %WINDIR%\Installer\$PatchCache$\UnManaged\S-1-5-21-2052111302-484763869-725345543-1003\ECA4C51A1C012664994065E6E70C4D4F\1.1.0\Psapi.Dll.C683356A_3C1A_49D7_BC37_3DBA6683C879
- %CommonProgramFiles%\Command Software\~GLH000a.TMP
- %PROGRAM_FILES%\EarthLink\~GLH000b.TMP
- <SYSTEM32>\AuthFw.exe
- <DRIVERS>\GRFilter.sys
- <DRIVERS>\GRTdiMon.sys
- %PROGRAM_FILES%\EarthLink\~GLH000c.TMP
- <SYSTEM32>\~GLH0011.TMP
- <SYSTEM32>\~GLH0012.TMP
- <SYSTEM32>\~GLH0013.TMP
- %PROGRAM_FILES%\EarthLink\~GLH000d.TMP
- <SYSTEM32>\~GLH000e.TMP
- <SYSTEM32>\~GLH0010.TMP
- %PROGRAM_FILES%\EarthLink\~GLH0038.TMP
- %PROGRAM_FILES%\EarthLink\~GLH0039.TMP
- %PROGRAM_FILES%\EarthLink\~GLH003a.TMP
- %ALLUSERSPROFILE%\Desktop\EarthLink Protection Control Center.lnk
- %PROGRAM_FILES%\EarthLink\~GLH0036.TMP
- <DRIVERS>\~GLH0037.TMP
- %PROGRAM_FILES%\EarthLink\~GLH003b.TMP
- %PROGRAM_FILES%\EarthLink\AutoConfig.dat
- %PROGRAM_FILES%\EarthLink\1.gif
- %PROGRAM_FILES%\EarthLink\10.gif
- C:\ADSService.txt
- %PROGRAM_FILES%\EarthLink\INSTALL.LOG
- %PROGRAM_FILES%\EarthLink\300.gif
- %PROGRAM_FILES%\EarthLink\~GLH002c.TMP
- %PROGRAM_FILES%\EarthLink\~GLH002d.TMP
- %PROGRAM_FILES%\EarthLink\~GLH002e.TMP
- %PROGRAM_FILES%\EarthLink\~GLH0029.TMP
- %PROGRAM_FILES%\EarthLink\~GLH002a.TMP
- %PROGRAM_FILES%\EarthLink\~GLH002b.TMP
- %PROGRAM_FILES%\EarthLink\~GLH002f.TMP
- %PROGRAM_FILES%\EarthLink\~GLH0035.TMP
- %ALLUSERSPROFILE%\Start Menu\Programs\EarthLink Protection Control Center\Uninstall EarthLink Protection Control Center.lnk
- %ALLUSERSPROFILE%\Start Menu\Programs\EarthLink Protection Control Center\EarthLink Protection Control Center.lnk
- %PROGRAM_FILES%\EarthLink\~GLH0031.TMP
- %PROGRAM_FILES%\EarthLink\~GLH0033.TMP
- %PROGRAM_FILES%\EarthLink\~GLH0034.TMP
- %WINDIR%\Installer\MSI9.tmp
- %WINDIR%\Installer\MSIA.tmp
- %APPDATA%\Microsoft\CryptnetUrlCache\MetaData\A8FABA189DB7D25FBA7CAC806625FD30
- %APPDATA%\Microsoft\CryptnetUrlCache\Content\A8FABA189DB7D25FBA7CAC806625FD30
- %WINDIR%\Installer\MSI8.tmp
- %TEMP%\nosign2.def
- %CommonProgramFiles%\Command Software\dvpmgr.exe
- %CommonProgramFiles%\Command Software\dvpnt.inf
- <DRIVERS>\css-dvp.sys
- %WINDIR%\Installer\MSIB.tmp
- C:\Config.Msi\2aca4.rbs
- %CommonProgramFiles%\Command Software\dvpapi.exe
- %TEMP%\~GLH0000.TMP
- %TEMP%\~GLH0001.TMP
- <SYSTEM32>\~GLH0002.TMP
- %TEMP%\GLC1.tmp
- %TEMP%\GLJ2.tmp
- %TEMP%\GLG4.tmp
- <SYSTEM32>\temp.000
- %WINDIR%\Installer\2aca1.msi
- %APPDATA%\Microsoft\CryptnetUrlCache\MetaData\60E31627FDA0A46932B0E5948949F2A5
- %APPDATA%\Microsoft\CryptnetUrlCache\Content\60E31627FDA0A46932B0E5948949F2A5
- <SYSTEM32>\~GLH0004.TMP
- <SYSTEM32>\~GLH0006.TMP
- %PROGRAM_FILES%\EarthLink\ins\~GLH0008.TMP
- %CommonProgramFiles%\Command Software\avevent.exe
- <SYSTEM32>\avmontr.dll
- %CommonProgramFiles%\Command Software\odapi.dll
- %CommonProgramFiles%\Command Software\csscan32.dll
- %CommonProgramFiles%\Command Software\css3rde.dll
- %CommonProgramFiles%\Command Software\atl70.dll
- %TEMP%\dvpmgr.log
- %WINDIR%\Installer\MSIE.tmp
- %WINDIR%\Installer\MSIF.tmp
- C:\Config.Msi\2aca9.rbs
- %CommonProgramFiles%\Command Software\rescue.dat
- %PROGRAM_FILES%\EarthLink\ins\~GLH0009.TMP
- %WINDIR%\Installer\2aca6.msi
- %CommonProgramFiles%\Command Software\FIXDISK.EXE
- %CommonProgramFiles%\Command Software\fixdsknt.exe
- %CommonProgramFiles%\Command Software\f-prot.exe
- %CommonProgramFiles%\Command Software\css-dvp.cat
- %CommonProgramFiles%\Command Software\css3rdem.dll
- %CommonProgramFiles%\Command Software\english.tx2
- %CommonProgramFiles%\Command Software\3rdeapi.dll
- %CommonProgramFiles%\Command Software\macro.def
- %CommonProgramFiles%\Command Software\defvn.dll
- %CommonProgramFiles%\Command Software\english.tx1
- %CommonProgramFiles%\Command Software\sign2.def
- %CommonProgramFiles%\Command Software\nomacro.def
- %CommonProgramFiles%\Command Software\sign.def
- %PROGRAM_FILES%\EarthLink\~GLH002f.TMP
- %PROGRAM_FILES%\EarthLink\~GLH0031.TMP
- %TEMP%\GLG4.tmp
- %PROGRAM_FILES%\EarthLink\~GLH001f.TMP
- %CommonProgramFiles%\Command Software\odapi.dll
- <SYSTEM32>\~GLH000e.TMP
- %PROGRAM_FILES%\EarthLink\~GLH001d.TMP
- %PROGRAM_FILES%\EarthLink\300.gif
- %PROGRAM_FILES%\EarthLink\1.gif
- %PROGRAM_FILES%\EarthLink\10.gif
- %TEMP%\GLC1.tmp
- %TEMP%\GLJ2.tmp
- %TEMP%\GLF5.tmp
- %TEMP%\GLF6.tmp
- %WINDIR%\Installer\2aca8.ipi
- %WINDIR%\Installer\MSI9.tmp
- %WINDIR%\Installer\MSIA.tmp
- %WINDIR%\Installer\MSIB.tmp
- %WINDIR%\Installer\MSI8.tmp
- <SYSTEM32>\~GLH0002.TMP
- <SYSTEM32>\~GLH0004.TMP
- <SYSTEM32>\~GLH0006.TMP
- %WINDIR%\Installer\MSIF.tmp
- C:\Config.Msi\2aca9.rbs
- %WINDIR%\Installer\2aca6.msi
- %WINDIR%\Installer\MSIE.tmp
- C:\Config.Msi\2aca4.rbs
- %WINDIR%\Installer\2aca1.msi
- %WINDIR%\Installer\2aca3.ipi
- from %PROGRAM_FILES%\EarthLink\~GLH002a.TMP to %PROGRAM_FILES%\EarthLink\ClientAVUpTls.dll
- from %PROGRAM_FILES%\EarthLink\~GLH0029.TMP to %PROGRAM_FILES%\EarthLink\Progbar.gif
- from %PROGRAM_FILES%\EarthLink\~GLH0028.TMP to %PROGRAM_FILES%\EarthLink\PlayGifo.ocx
- from %PROGRAM_FILES%\EarthLink\~GLH002d.TMP to %PROGRAM_FILES%\EarthLink\HoverImageButton.ocx
- from %PROGRAM_FILES%\EarthLink\~GLH002c.TMP to %PROGRAM_FILES%\EarthLink\HoverMenu.ocx
- from %PROGRAM_FILES%\EarthLink\~GLH002b.TMP to %PROGRAM_FILES%\EarthLink\EFWPPService.exe
- from %PROGRAM_FILES%\EarthLink\~GLH0027.TMP to %PROGRAM_FILES%\EarthLink\asee.dll
- from %PROGRAM_FILES%\EarthLink\Dats\~GLH0023.TMP to %PROGRAM_FILES%\EarthLink\Dats\Config.dat
- from %PROGRAM_FILES%\EarthLink\~GLH0022.TMP to %PROGRAM_FILES%\EarthLink\elnkserv.exe
- from %PROGRAM_FILES%\EarthLink\~GLH0021.TMP to %PROGRAM_FILES%\EarthLink\fwwhtlst.dat
- from <SYSTEM32>\~GLH0026.TMP to <SYSTEM32>\ASE.dll
- from <SYSTEM32>\~GLH0025.TMP to <SYSTEM32>\AluriaReg.dll
- from %PROGRAM_FILES%\EarthLink\Dats\~GLH0024.TMP to %PROGRAM_FILES%\EarthLink\Dats\Syg.dat
- from %PROGRAM_FILES%\EarthLink\~GLH002e.TMP to %PROGRAM_FILES%\EarthLink\UserCleanup.exe
- from %PROGRAM_FILES%\EarthLink\~GLH0038.TMP to %PROGRAM_FILES%\EarthLink\ADSFilter.inf
- from <DRIVERS>\~GLH0037.TMP to <DRIVERS>\ADSFilter.sys
- from %PROGRAM_FILES%\EarthLink\~GLH0036.TMP to %PROGRAM_FILES%\EarthLink\ADSFilter.sys
- from %PROGRAM_FILES%\EarthLink\~GLH003b.TMP to %PROGRAM_FILES%\EarthLink\IUtills.exe
- from %PROGRAM_FILES%\EarthLink\~GLH003a.TMP to %PROGRAM_FILES%\EarthLink\ads.dll
- from %PROGRAM_FILES%\EarthLink\~GLH0039.TMP to %PROGRAM_FILES%\EarthLink\adsservice.exe
- from %PROGRAM_FILES%\EarthLink\~GLH0035.TMP to %PROGRAM_FILES%\EarthLink\wscapi.dll
- from %PROGRAM_FILES%\EarthLink\temp.000 to %PROGRAM_FILES%\EarthLink\~GLH0032.TMP
- from %PROGRAM_FILES%\EarthLink\~GLH0030.TMP to %PROGRAM_FILES%\EarthLink\elaccess.dll
- from %PROGRAM_FILES%\EarthLink\temp.000 to %PROGRAM_FILES%\EarthLink\~GLH0030.TMP
- from %PROGRAM_FILES%\EarthLink\~GLH0034.TMP to %PROGRAM_FILES%\EarthLink\mainFWRemove.exe
- from %PROGRAM_FILES%\EarthLink\~GLH0033.TMP to %PROGRAM_FILES%\EarthLink\KP.exe
- from %PROGRAM_FILES%\EarthLink\~GLH0032.TMP to %PROGRAM_FILES%\EarthLink\asavfwre.exe
- from %TEMP%\nosign2.def to %CommonProgramFiles%\Command Software\nosign2.def
- from %PROGRAM_FILES%\EarthLink\ins\~GLH0008.TMP to %PROGRAM_FILES%\EarthLink\ins\avsdk.msi
- from <SYSTEM32>\~GLH0007.TMP to <SYSTEM32>\vbar332.dll
- from %PROGRAM_FILES%\EarthLink\~GLH000b.TMP to %PROGRAM_FILES%\EarthLink\UNWISE.EXE
- from %CommonProgramFiles%\Command Software\~GLH000a.TMP to %CommonProgramFiles%\Command Software\odapi.dll
- from %PROGRAM_FILES%\EarthLink\ins\~GLH0009.TMP to %PROGRAM_FILES%\EarthLink\ins\AuthFW.msi
- from <SYSTEM32>\temp.000 to <SYSTEM32>\~GLH0007.TMP
- from <SYSTEM32>\temp.000 to <SYSTEM32>\~GLH0003.TMP
- from %TEMP%\~GLH0001.TMP to %TEMP%\GLF6.tmp
- from %TEMP%\~GLH0000.TMP to %TEMP%\GLF5.tmp
- from <SYSTEM32>\~GLH0005.TMP to <SYSTEM32>\COMDLG32.OCX
- from <SYSTEM32>\temp.000 to <SYSTEM32>\~GLH0005.TMP
- from <SYSTEM32>\~GLH0003.TMP to <SYSTEM32>\MSCOMCTL.OCX
- from %PROGRAM_FILES%\EarthLink\~GLH000c.TMP to %PROGRAM_FILES%\EarthLink\pcc.chm
- from %PROGRAM_FILES%\EarthLink\temp.000 to %PROGRAM_FILES%\EarthLink\~GLH001e.TMP
- from <SYSTEM32>\~GLH001c.TMP to <SYSTEM32>\aamd532.dll
- from <SYSTEM32>\~GLH0014.TMP to <SYSTEM32>\Msstdfmt.dll
- from %PROGRAM_FILES%\EarthLink\~GLH0020.TMP to %PROGRAM_FILES%\EarthLink\Lang_US.dll
- from %PROGRAM_FILES%\EarthLink\temp.000 to %PROGRAM_FILES%\EarthLink\~GLH0020.TMP
- from %PROGRAM_FILES%\EarthLink\~GLH001e.TMP to %PROGRAM_FILES%\EarthLink\elnk_pcc.exe
- from <SYSTEM32>\~GLH0013.TMP to <SYSTEM32>\RICHTX32.OCX
- from <SYSTEM32>\~GLH000f.TMP to <SYSTEM32>\unicows.dll
- from <SYSTEM32>\temp.000 to <SYSTEM32>\~GLH000f.TMP
- from %PROGRAM_FILES%\EarthLink\~GLH000d.TMP to %PROGRAM_FILES%\EarthLink\SRS.dll
- from <SYSTEM32>\~GLH0012.TMP to <SYSTEM32>\MSINET.OCX
- from <SYSTEM32>\~GLH0011.TMP to <SYSTEM32>\MSCOMCT2.OCX
- from <SYSTEM32>\~GLH0010.TMP to <SYSTEM32>\MSCOMM32.OCX
- 'cs######4-crl.verisign.com':80
- 'crl.verisign.com':80
- 'wp#d':80
- cs######4-crl.verisign.com/CSC3-2004.crl
- crl.verisign.com/pca3.crl
- wp#d/wpad.dat
- DNS ASK cs######4-crl.verisign.com
- DNS ASK crl.verisign.com
- DNS ASK wp#d
- ClassName: '18467-41' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''