Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '<Full path to virus>' = '<Full path to virus>:*:Enabled:FoxTab Music Converter Installer'
- %TEMP%\ish129468\images\skip-button.png
- %TEMP%\ish129468\images\progress-bg.png
- %TEMP%\ish129468\license.txt
- %TEMP%\ish129468\images\Software.png
- %TEMP%\ish129468\images\next-button.png
- %TEMP%\ish129468\images\icon.png
- %TEMP%\ish129468\images\finish_button.jpg
- %TEMP%\ish129468\images\next-button-over.png
- %TEMP%\ish129468\images\loader.gif
- %TEMP%\ish129468\locale\EN.locale
- %TEMP%\00029205.log
- %HOMEPATH%\Desktop\Continue FoxTab Music Converter Installation.lnk
- %TEMP%\is1972027439\1572444273.cfg
- %TEMP%\is1972027439\131593377.cfg
- %TEMP%\ICReinstall\<Virus name>.exe
- %PROGRAM_FILES%\is163562.log
- %TEMP%\ish129468\bootstrap_23254.html
- %TEMP%\0002813C.log
- %TEMP%\00028061.log
- %TEMP%\ish129468\css\sdk-ui\button.css
- %TEMP%\ish129468\css\sdk-ui\browse.css
- %TEMP%\ish129468\css\sdk-ui\images\button-bg.png
- %TEMP%\ish129468\css\sdk-ui\checkbox.css
- %TEMP%\ish129468\css\main.css
- %TEMP%\ish129468\blank.gif
- %TEMP%\0001F8A3.log
- %TEMP%\ish129468\css\ie6_main.css
- %TEMP%\ish129468\css\buttons.css
- %TEMP%\ish129468\css\sdk-ui\images\progress-bg.png
- %TEMP%\ish129468\images\Bg.jpg
- %TEMP%\ish129468\images\back-button.png
- %TEMP%\ish129468\images\finish-button.png
- %TEMP%\ish129468\images\close_button.png
- %TEMP%\ish129468\defaultOffer\US\offer_html.dat
- %TEMP%\ish129468\defaultOffer\offer_code.dat
- %TEMP%\ish129468\css\sdk-ui\progress-bar.css
- %TEMP%\ish129468\defaultOffer\US\offer_code.dat
- %TEMP%\ish129468\defaultOffer\offer_html.dat
- %TEMP%\0002813C.log
- %TEMP%\00029205.log
- %TEMP%\ish129468\bootstrap_23254.html
- %TEMP%\0001F8A3.log
- %PROGRAM_FILES%\is163562.log
- %TEMP%\00028061.log
- 'cd###.solvefile.com':80
- 'os.###vefile.com':80
- cd###.solvefile.com/Prod/AudioConverter-v2.cis
- os.###vefile.com/fx/v1.0.1/?v=###############
- DNS ASK cd###.solvefile.com
- DNS ASK os.###vefile.com
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''