Technical Information
- '<SYSTEM32>\getmac.exe' /v /fo table /nh
- %TEMP%\ish161984\images\Progress.png
- %TEMP%\ish161984\images\Logo.png
- %TEMP%\ish161984\images\sponsored.png
- %TEMP%\ish161984\images\ProgressBar.png
- %TEMP%\ish161984\images\Grey_Button.png
- %TEMP%\ish161984\images\default_tb.png
- %TEMP%\ish161984\images\Loader.gif
- %TEMP%\ish161984\images\Grey_Button_Hover.png
- %TEMP%\ish161984\images\welcome_bg.png
- %TEMP%\0002BA8C.log
- %TEMP%\0002B9E0.log
- %HOMEPATH%\Desktop\Continue LiveiStream Installation.lnk
- %TEMP%\ICReinstall_<Virus name>.exe
- %TEMP%\ish161984\bootstrap_46190.html
- %TEMP%\ish161984\locale\EN.locale
- %TEMP%\0002B972.log
- %PROGRAM_FILES%\is171921.log
- %TEMP%\ish161984\images\Color_Button_Hover.png
- %TEMP%\ish161984\css\sdk-ui\checkbox.css
- %TEMP%\ish161984\css\sdk-ui\button.css
- %TEMP%\ish161984\css\sdk-ui\images\progress-bg-corner.png
- %TEMP%\ish161984\css\sdk-ui\images\button-bg.png
- %TEMP%\ish161984\css\ie6_main.css
- %TEMP%\00027833.log
- %TEMP%\ish161984\css\sdk-ui\browse.css
- %TEMP%\ish161984\css\main.css
- %TEMP%\ish161984\css\sdk-ui\images\progress-bg.png
- %TEMP%\ish161984\images\Close.png
- %TEMP%\ish161984\images\BG.png
- %TEMP%\ish161984\images\Color_Button.png
- %TEMP%\ish161984\images\Close_Hover.png
- %TEMP%\ish161984\css\sdk-ui\progress-bar.css
- %TEMP%\ish161984\css\sdk-ui\images\progress-bg2.png
- %TEMP%\ish161984\form.bmp.Mask
- %TEMP%\ish161984\csshover3.htc
- %TEMP%\0002B9E0.log
- %TEMP%\0002BA8C.log
- %TEMP%\ish161984\bootstrap_46190.html
- %TEMP%\00027833.log
- %PROGRAM_FILES%\is171921.log
- %TEMP%\0002B972.log
- 'os.###etowemi.com':80
- os.###etowemi.com/WhiteSmoke/?v=################
- DNS ASK os#.##tetowemi.com
- DNS ASK cd###.#otetowemi.com
- DNS ASK os.###etowemi.com
- ClassName: 'MS_WebcheckMonitor' WindowName: '(null)'
- ClassName: 'MS_AutodialMonitor' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'