Technical Information
- '<LS_APPDATA>\temp\2552Installer.exe' /KEYWORD=2552 "/PATHFILES=<LS_APPDATA>\temp\"
- '%TEMP%\1387829363itinstallerp.exe'
- %TEMP%\square_boxore_tp.bmp
- %TEMP%\mypcbackup_image1.bmp
- %TEMP%\logo-highliteapp.bmp
- %TEMP%\logo-kingbrowse.bmp
- %TEMP%\pricemeter_image.bmp
- %TEMP%\mypcbackup_title.bmp
- %TEMP%\nst4.tmp\modern-header.bmp
- %TEMP%\nst4.tmp\modern-wizard.bmp
- %TEMP%\config.xml
- %TEMP%\costmin_moreinfo.bmp
- %TEMP%\square_saveclicker_developer.bmp
- %TEMP%\square_saveclicker.bmp
- %TEMP%\sharpsavings_image1.bmp
- %TEMP%\square_lollipop.bmp
- %TEMP%\square_sharpsavings.bmp
- %TEMP%\falcon_image1.bmp
- %TEMP%\square_vbates.bmp
- %TEMP%\lollipop_moreinfo.bmp
- %TEMP%\square_vuupc.bmp
- %TEMP%\square_webstroller_softpublisher.bmp
- %TEMP%\systemspeedup_image.bmp
- %TEMP%\square_pcfaster.bmp
- %TEMP%\pcfaster_logo.bmp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\instapi[3].php
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\instapi[4].php
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\instapi[3].php
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\instapi[3].php
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\instapi[3].php
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\instapi[4].php
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\instapi[5].php
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\instapi[5].php
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\instapi[5].php
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\instapi[4].php
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\instapi[4].php
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\instapi[2].php
- %TEMP%\nst4.tmp\nsArray.dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\instapi[1].php
- %TEMP%\nst4.tmp\nsURL.dll
- %TEMP%\nst4.tmp\ButtonEvent.dll
- %TEMP%\nst4.tmp\System.dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\instapi[1].php
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\instapi[2].php
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\instapi[2].php
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\instapi[2].php
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\instapi[1].php
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\instapi[1].php
- %TEMP%\square_falcon.bmp
- %TEMP%\instloffer.exe
- %TEMP%\snapdo_terms.rtf
- %TEMP%\ajax_loader.gif
- %TEMP%\nst4.tmp\tkDecript.dll
- %TEMP%\license.rtf
- %TEMP%\hao123_image1.bmp
- %TEMP%\tb_utilsbar.bmp
- %TEMP%\square_aartemis.bmp
- %TEMP%\square_utilsbar.bmp
- %TEMP%\mysearchdial_chrome_image1.bmp
- %TEMP%\mysearchdial_msie_firefox_image.bmp
- %TEMP%\nst4.tmp\version.dll
- %TEMP%\loader.bmp
- %TEMP%\icon.ico
- %TEMP%\1387829363itinstallerp.exe
- %TEMP%\nsw2.tmp\System.dll
- %TEMP%\nsw2.tmp\tkDecript.dll
- <LS_APPDATA>\temp\2552Installer.exe
- <LS_APPDATA>\temp\2552header.bmp.zip
- %TEMP%\header.bmp
- %TEMP%\fondo.bmp
- <LS_APPDATA>\temp\2552Installer.INI
- <LS_APPDATA>\temp\2552fondo.bmp.zip
- %TEMP%\bubbledock_image1.bmp
- %TEMP%\square_irobinhood.bmp
- %TEMP%\square_bubbledock.bmp
- %TEMP%\square_pricepeep.bmp
- %TEMP%\richtext1.rtf
- %TEMP%\irobinhood_image1.bmp
- %TEMP%\tubedimmer_sample.bmp
- %TEMP%\tubedimmer_logo.bmp
- %TEMP%\square_tubedimmer.bmp
- %TEMP%\square_baseflash.bmp
- %TEMP%\square_weatherapp.bmp
- %TEMP%\pricepeep_logo.bmp
- %TEMP%\optimizerpro_name.bmp
- %TEMP%\optimizerpro_image1.bmp
- %TEMP%\optimizerpro_title.bmp
- %TEMP%\passwidget_image3.bmp
- %TEMP%\square_passwidget.bmp
- %TEMP%\square_optimizerpro.bmp
- %TEMP%\3dboxes_pcspeedup.bmp
- %TEMP%\logo_pcspeedup.bmp
- %TEMP%\square_pcspeedup.bmp
- %TEMP%\square_softwareupdater.bmp
- %TEMP%\mockup_softwareupdater.bmp
- %TEMP%\icon.ico
- <LS_APPDATA>\temp\2552fondo.bmp.zip
- <LS_APPDATA>\temp\2552header.bmp.zip
- %TEMP%\nsw2.tmp\System.dll
- %TEMP%\nsw2.tmp\tkDecript.dll
- %TEMP%\loader.bmp
- from %TEMP%\header.bmp to <LS_APPDATA>\temp\2552header.bmp
- from %TEMP%\fondo.bmp to <LS_APPDATA>\temp\2552fondo.bmp
- 'www.in##seo.com':80
- 'xm####tcp.ddbbvt.eu':80
- www.in##seo.com/insts/instapi.php?id###################################################################
- www.in##seo.com/insts/instapi.php?id####################################################################
- xm####tcp.ddbbvt.eu/cmd/precompiled.html?q=#########################
- www.in##seo.com/insts/instapi.php?id##################################################
- DNS ASK www.dl##ovt.com
- DNS ASK www.in##seo.com
- DNS ASK xm####tcp.ddbbvt.eu
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'