Technical Information
- %TEMP%\is-7l4ue.tmp\is-fhq7t.tmp
- %ProgramFiles(x86)%\fmz drive recovery\unins000.dat
- %ProgramFiles(x86)%\fmz drive recovery\is-tqmvr.tmp
- %ProgramFiles(x86)%\fmz drive recovery\is-ae4je.tmp
- %ProgramFiles(x86)%\fmz drive recovery\is-agtsj.tmp
- %ProgramFiles(x86)%\fmz drive recovery\is-f3u5s.tmp
- %ProgramFiles(x86)%\fmz drive recovery\is-ua9oj.tmp
- %ProgramFiles(x86)%\fmz drive recovery\is-r5n0v.tmp
- %ProgramFiles(x86)%\fmz drive recovery\is-b0q8n.tmp
- %ProgramFiles(x86)%\fmz drive recovery\is-qna2g.tmp
- %ProgramFiles(x86)%\fmz drive recovery\is-1oq64.tmp
- %ProgramFiles(x86)%\fmz drive recovery\is-28cfg.tmp
- %ProgramFiles(x86)%\fmz drive recovery\is-ee4o7.tmp
- %ProgramFiles(x86)%\fmz drive recovery\is-d3em7.tmp
- %ProgramFiles(x86)%\fmz drive recovery\is-6hvel.tmp
- %ProgramFiles(x86)%\fmz drive recovery\frecover.exe
- %ProgramFiles(x86)%\fmz drive recovery\is-qg806.tmp
- %ProgramFiles(x86)%\fmz drive recovery\is-9ugk7.tmp
- %ProgramFiles(x86)%\fmz drive recovery\is-49osf.tmp
- %ProgramFiles(x86)%\fmz drive recovery\is-5re8b.tmp
- %ProgramFiles(x86)%\fmz drive recovery\is-8fd6c.tmp
- %ProgramFiles(x86)%\fmz drive recovery\is-q8n3r.tmp
- %ProgramFiles(x86)%\fmz drive recovery\is-qevtp.tmp
- %ProgramFiles(x86)%\fmz drive recovery\is-e9fh7.tmp
- %ProgramFiles(x86)%\fmz drive recovery\is-f3ihi.tmp
- %ProgramFiles(x86)%\fmz drive recovery\is-ju609.tmp
- %ProgramFiles(x86)%\fmz drive recovery\is-1eq4s.tmp
- %TEMP%\is-dlho1.tmp\_isetup\_iscrypt.dll
- %TEMP%\is-dlho1.tmp\_isetup\_shfoldr.dll
- %TEMP%\is-dlho1.tmp\_isetup\_setup64.tmp
- %TEMP%\is-dlho1.tmp\_isetup\_regdll.tmp
- %ProgramFiles(x86)%\fmz drive recovery\is-j2sbb.tmp
- %TEMP%\iobit.cab
- from %ProgramFiles(x86)%\fmz drive recovery\is-1eq4s.tmp to %ProgramFiles(x86)%\fmz drive recovery\unins000.exe
- from %ProgramFiles(x86)%\fmz drive recovery\is-agtsj.tmp to %ProgramFiles(x86)%\fmz drive recovery\pt.lan
- from %ProgramFiles(x86)%\fmz drive recovery\is-f3u5s.tmp to %ProgramFiles(x86)%\fmz drive recovery\ar.lan
- from %ProgramFiles(x86)%\fmz drive recovery\is-ua9oj.tmp to %ProgramFiles(x86)%\fmz drive recovery\sk.lan
- from %ProgramFiles(x86)%\fmz drive recovery\is-r5n0v.tmp to %ProgramFiles(x86)%\fmz drive recovery\pl.lan
- from %ProgramFiles(x86)%\fmz drive recovery\is-b0q8n.tmp to %ProgramFiles(x86)%\fmz drive recovery\fa.lan
- from %ProgramFiles(x86)%\fmz drive recovery\is-qna2g.tmp to %ProgramFiles(x86)%\fmz drive recovery\cnt.lan
- from %ProgramFiles(x86)%\fmz drive recovery\is-1oq64.tmp to %ProgramFiles(x86)%\fmz drive recovery\cn.lan
- from %ProgramFiles(x86)%\fmz drive recovery\is-28cfg.tmp to %ProgramFiles(x86)%\fmz drive recovery\it.lan
- from %ProgramFiles(x86)%\fmz drive recovery\is-ee4o7.tmp to %ProgramFiles(x86)%\fmz drive recovery\fin.lan
- from %ProgramFiles(x86)%\fmz drive recovery\is-d3em7.tmp to %ProgramFiles(x86)%\fmz drive recovery\bg.lan
- from %ProgramFiles(x86)%\fmz drive recovery\is-ae4je.tmp to %ProgramFiles(x86)%\fmz drive recovery\turbosearch.exe
- from %ProgramFiles(x86)%\fmz drive recovery\is-6hvel.tmp to %ProgramFiles(x86)%\fmz drive recovery\tr.lan
- from %ProgramFiles(x86)%\fmz drive recovery\is-j2sbb.tmp to %ProgramFiles(x86)%\fmz drive recovery\es.lan
- from %ProgramFiles(x86)%\fmz drive recovery\is-9ugk7.tmp to %ProgramFiles(x86)%\fmz drive recovery\ro.lan
- from %ProgramFiles(x86)%\fmz drive recovery\is-49osf.tmp to %ProgramFiles(x86)%\fmz drive recovery\hu.lan
- from %ProgramFiles(x86)%\fmz drive recovery\is-5re8b.tmp to %ProgramFiles(x86)%\fmz drive recovery\ru.lan
- from %ProgramFiles(x86)%\fmz drive recovery\is-8fd6c.tmp to %ProgramFiles(x86)%\fmz drive recovery\de.lan
- from %ProgramFiles(x86)%\fmz drive recovery\is-q8n3r.tmp to %ProgramFiles(x86)%\fmz drive recovery\fr.lan
- from %ProgramFiles(x86)%\fmz drive recovery\is-qevtp.tmp to %ProgramFiles(x86)%\fmz drive recovery\en.lan
- from %ProgramFiles(x86)%\fmz drive recovery\is-e9fh7.tmp to %ProgramFiles(x86)%\fmz drive recovery\frecover.exe.manifest
- from %ProgramFiles(x86)%\fmz drive recovery\is-f3ihi.tmp to %ProgramFiles(x86)%\fmz drive recovery\license.txt
- from %ProgramFiles(x86)%\fmz drive recovery\is-ju609.tmp to %ProgramFiles(x86)%\fmz drive recovery\readme.txt
- from %ProgramFiles(x86)%\fmz drive recovery\is-qg806.tmp to %ProgramFiles(x86)%\fmz drive recovery\du.lan
- from %ProgramFiles(x86)%\fmz drive recovery\is-tqmvr.tmp to %ProgramFiles(x86)%\fmz drive recovery\frecover.exe
- 'tu####lotneli.cf':80
- http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?56#######
- http://tu####lotneli.cf/new/net_api
- DNS ASK tu####lotneli.cf
- ClassName: '' WindowName: 'FmzbitsWindowClassFmz29'
- '%TEMP%\is-7l4ue.tmp\is-fhq7t.tmp' /SL4 $11022C "<Full path to file>" 4738430 73216
- '%ProgramFiles(x86)%\fmz drive recovery\frecover.exe'
- '%ProgramFiles(x86)%\fmz drive recovery\frecover.exe' 0ea676d79db5be6a9bde66845bceda5c
- '%WINDIR%\syswow64\schtasks.exe' /Query
- '%WINDIR%\syswow64\schtasks.exe' /Delete /F /TN "frecover"