Technical Information
- %HOMEPATH%\Start Menu\Programs\Startup\StartHelp.lnk
- '<SYSTEM32>\wscript.exe' "%APPDATA%\windowsold1\launchURL_956.vbs"
- '<SYSTEM32>\wscript.exe' "%APPDATA%\windowsold1\launchURL_940.vbs"
- '<SYSTEM32>\wscript.exe' "%APPDATA%\windowsold1\launchURL_989.vbs"
- '<SYSTEM32>\wscript.exe' "%APPDATA%\windowsold1\launchURL_972.vbs"
- '<SYSTEM32>\wscript.exe' "%APPDATA%\windowsold1\IsAlive.vbs"
- '<SYSTEM32>\wscript.exe' "%APPDATA%\windowsold1\UpdateUser.vbs"
- '<SYSTEM32>\wscript.exe' "%APPDATA%\windowsold1\RHelp.vbs"
- '<SYSTEM32>\wscript.exe' "%APPDATA%\windowsold1\SHORTCUT.VBS"
- '%ProgramFiles%\Internet Explorer\IEXPLORE.EXE' -Embedding
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4] '2500' = '00000003'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1] '1609' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2] '2500' = '00000003'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '2500' = '00000003'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4] '1609' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4] 'AutoRecover' = '00000002'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2] '1609' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1609' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1] '2500' = '00000001'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1609' = '00000001'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1A10' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] 'CurrentLevel' = '00011500'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '2500' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1A05' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1A06' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1A02' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1A03' = '00000000'
- %APPDATA%\windowsold1\launchURL_956.vbs
- %APPDATA%\windowsold1\launchURL_972.vbs
- %HOMEPATH%\Local Settings\<INETFILES>\36\Content.IE5\QN32N898\desktop.ini
- %HOMEPATH%\Local Settings\<INETFILES>\36\Content.IE5\OF81CLQN\desktop.ini
- %HOMEPATH%\Local Settings\<INETFILES>\36\Content.IE5\57ZWAHFS\where-the-us-and-eu-get-their-fuel-2014-7[1]
- %HOMEPATH%\Local Settings\<INETFILES>\36\Content.IE5\QN32N898\wall-street-week-ahead-giving-thanks-for-big-stock-gains-114112200081_1[1].html
- %HOMEPATH%\Local Settings\<INETFILES>\36\Content.IE5\OF81CLQN\george-soros-give-ex-pimcos-bill-gross-500m-invest-1475888[1]
- %APPDATA%\windowsold1\launchURL_989.vbs
- %HOMEPATH%\Local Settings\<INETFILES>\36\Content.IE5\CH67STQV\15839121[1]
- %APPDATA%\windowsold1\SHORTCUT.VBS
- %APPDATA%\windowsold1\RHelp.vbs
- %APPDATA%\windowsold1\UpdateUser.vbs
- %APPDATA%\windowsold1\IsAlive.vbs
- %APPDATA%\windowsold1\launchURL_940.vbs
- %HOMEPATH%\Local Settings\<INETFILES>\36\Content.IE5\57ZWAHFS\desktop.ini
- %HOMEPATH%\Local Settings\<INETFILES>\36\Content.IE5\CH67STQV\desktop.ini
- %HOMEPATH%\Local Settings\<INETFILES>\36\desktop.ini
- %HOMEPATH%\Local Settings\<INETFILES>\36\Content.IE5\desktop.ini
- %HOMEPATH%\Local Settings\<INETFILES>\36\Content.IE5\CH67STQV\desktop.ini
- %HOMEPATH%\Local Settings\<INETFILES>\36\Content.IE5\QN32N898\desktop.ini
- %HOMEPATH%\Local Settings\<INETFILES>\36\Content.IE5\OF81CLQN\desktop.ini
- %HOMEPATH%\Local Settings\<INETFILES>\36\desktop.ini
- %HOMEPATH%\Local Settings\<INETFILES>\36\Content.IE5\desktop.ini
- %HOMEPATH%\Local Settings\<INETFILES>\36\Content.IE5\57ZWAHFS\desktop.ini
- %APPDATA%\windowsold1\launchURL_940.vbs
- %APPDATA%\windowsold1\launchURL_956.vbs
- %APPDATA%\windowsold1\launchURL_989.vbs
- %APPDATA%\windowsold1\SHORTCUT.VBS
- %APPDATA%\windowsold1\UpdateUser.vbs
- %APPDATA%\windowsold1\RHelp.vbs
- 'www.cn##.com':80
- 'www.bu#####s-standard.com':80
- 'www.ib###es.co.uk':80
- '74.##5.232.51':80
- 'localhost':1040
- 'www.bu####ssinsider.com':80
- http://www.bu#####s-standard.com/article/reuters/wall-street-week-ahead-giving-thanks-for-big-stock-gains-114112200081_1.html
- http://www.ib###es.co.uk/george-soros-give-ex-pimcos-bill-gross-500m-invest-1475888
- http://www.bu####ssinsider.com/where-the-us-and-eu-get-their-fuel-2014-7
- http://www.cn##.com/id/15839121?tr########################################
- DNS ASK www.bu#####s-standard.com
- DNS ASK www.ib###es.co.uk
- DNS ASK www.cn##.com
- DNS ASK www.google.com
- DNS ASK www.bu####ssinsider.com
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: '' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''