Technical Information
- '<LS_APPDATA>\temp\d09aInstaller.exe' /KEYWORD=d09a "/PATHFILES=<LS_APPDATA>\temp\"
- '%TEMP%\1396720099itinstallerp.exe'
- %TEMP%\moreinfo_offerbox.bmp
- %TEMP%\square_offerbox.bmp
- %TEMP%\lollipop_moreinfo.bmp
- %TEMP%\sharpsavings_image1.bmp
- %TEMP%\square_lollipop.bmp
- %TEMP%\square_pcfaster.bmp
- %TEMP%\square_webstroller_softpublisher.bmp
- %TEMP%\square_saveclicker.bmp
- %TEMP%\square_vuupc.bmp
- %TEMP%\pcfaster_logo.bmp
- %TEMP%\systemspeedup_image.bmp
- %TEMP%\freesofttoday_image1_fr.bmp
- %TEMP%\freesofttoday_image1_it.bmp
- %TEMP%\freesofttoday_image1_pt.bmp
- %TEMP%\square_freesofttoday.bmp
- %TEMP%\freesofttoday_image1_es.bmp
- %TEMP%\freesofttoday_image1_jp.bmp
- %TEMP%\square_vbates.bmp
- %TEMP%\square_sharpsavings.bmp
- %TEMP%\freesofttoday_image1_en.bmp
- %TEMP%\freesofttoday_image1_tr.bmp
- %TEMP%\freesofttoday_image1_pl.bmp
- %TEMP%\nsf4.tmp\System.dll
- %TEMP%\nsf4.tmp\nsURL.dll
- %TEMP%\nsf4.tmp\ButtonEvent.dll
- %TEMP%\nsf4.tmp\modern-header.bmp
- %TEMP%\nsf4.tmp\modern-wizard.bmp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\geo[1].php
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\api[1].php
- %TEMP%\nsf4.tmp\nsDialogs.dll
- %TEMP%\nsf4.tmp\nsArray.dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\abcde[1].php
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\api[1].php
- %TEMP%\moviemode-logo.bmp
- %TEMP%\pricemeter_image.bmp
- %TEMP%\moviemode-sample.bmp
- %TEMP%\logo-kingbrowse.bmp
- %TEMP%\square_moviemode.bmp
- %TEMP%\logo-highliteapp.bmp
- %TEMP%\costmin_moreinfo.bmp
- %TEMP%\config.xml
- %TEMP%\mypcbackup_title.bmp
- %TEMP%\square_boxore_tp.bmp
- %TEMP%\mypcbackup_image1.bmp
- %TEMP%\ajax_loader.gif
- %TEMP%\instloffer.exe
- %TEMP%\license.rtf
- %TEMP%\nsf4.tmp\version.dll
- %TEMP%\nsf4.tmp\tkDecript.dll
- %TEMP%\square_aartemis.bmp
- %TEMP%\passwidget_image3.bmp
- %TEMP%\square_passwidget.bmp
- %TEMP%\tb_utilsbar.bmp
- %TEMP%\snapdo_terms.rtf
- %TEMP%\square_utilsbar.bmp
- %TEMP%\loader.bmp
- %TEMP%\icon.ico
- %TEMP%\1396720099itinstallerp.exe
- %TEMP%\nsb2.tmp\System.dll
- %TEMP%\nsb2.tmp\tkDecript.dll
- <LS_APPDATA>\temp\d09aInstaller.exe
- <LS_APPDATA>\temp\d09aheader.bmp.zip
- %TEMP%\header.bmp
- %TEMP%\fondo.bmp
- <LS_APPDATA>\temp\d09aInstaller.INI
- <LS_APPDATA>\temp\d09afondo.bmp.zip
- %TEMP%\square_irobinhood.bmp
- %TEMP%\irobinhood_image1.bmp
- %TEMP%\bubbledock_image1.bmp
- %TEMP%\richtext1.rtf
- %TEMP%\square_bubbledock.bmp
- %TEMP%\square_baseflash.bmp
- %TEMP%\square_falcon.bmp
- %TEMP%\falcon_image1.bmp
- %TEMP%\tubedimmer_logo.bmp
- %TEMP%\square_tubedimmer.bmp
- %TEMP%\tubedimmer_sample.bmp
- %TEMP%\square_optimizerpro.bmp
- %TEMP%\square_softwareupdater.bmp
- %TEMP%\optimizerpro_image1.bmp
- %TEMP%\optimizerpro_title.bmp
- %TEMP%\optimizerpro_name.bmp
- %TEMP%\mockup_softwareupdater.bmp
- %TEMP%\pricepeep_logo.bmp
- %TEMP%\square_pricepeep.bmp
- %TEMP%\logo_pcspeedup.bmp
- %TEMP%\square_pcspeedup.bmp
- %TEMP%\3dboxes_pcspeedup.bmp
- %TEMP%\icon.ico
- <LS_APPDATA>\temp\d09afondo.bmp.zip
- <LS_APPDATA>\temp\d09aheader.bmp.zip
- %TEMP%\nsb2.tmp\System.dll
- %TEMP%\nsb2.tmp\tkDecript.dll
- %TEMP%\loader.bmp
- from %TEMP%\header.bmp to <LS_APPDATA>\temp\d09aheader.bmp
- from %TEMP%\fondo.bmp to <LS_APPDATA>\temp\d09afondo.bmp
- 'www.dl##ovt.com':80
- 'xm####tcp.eebbvt.eu':80
- xm####tcp.eebbvt.eu/cmd/report.php?mk##################################################################################################################################################################################################################
- xm####tcp.eebbvt.eu/cmd/api.php?mk##########################################
- xm####tcp.eebbvt.eu/cmd/report.php?mk###########################################################################################################################################################################################################
- xm####tcp.eebbvt.eu/cmd/log.php?U1##################################################################################################################################
- xm####tcp.eebbvt.eu/cmd/api.php?mk########################################################################
- xm####tcp.eebbvt.eu/cmd/geo.php?mk##################
- xm####tcp.eebbvt.eu/cmd/api.php?mk####################################
- www.dl##ovt.com/abcde.php
- DNS ASK www.dl##ovt.com
- DNS ASK xm####tcp.eebbvt.eu
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'