Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '<Full path to virus>' = '<Full path to virus>:*:Enabled:FoxTab MOV Converter Installer'
- %TEMP%\ish106125\images\skip-button.png
- %TEMP%\ish106125\images\progress-bg.png
- %TEMP%\ish106125\images\Software.png
- %TEMP%\ish106125\locale\EN.locale
- %TEMP%\ish106125\license.txt
- %TEMP%\ish106125\images\icon.png
- %TEMP%\ish106125\images\finish_button.jpg
- %TEMP%\ish106125\images\loader.gif
- %TEMP%\ish106125\images\next-button.png
- %TEMP%\ish106125\images\next-button-over.png
- %TEMP%\0001E857.log
- %PROGRAM_FILES%\is124031.log
- %TEMP%\is1972027439\182292433.cfg
- %TEMP%\is1972027439\1353966337.cfg
- %TEMP%\ish106125\sdk\jsdoc-gen.cmd
- %TEMP%\ish106125\sdk\exceptlist.txt
- %TEMP%\ish106125\sdk\version-history.txt
- %TEMP%\0001DFDB.log
- %TEMP%\ish106125\bootstrap_60936.html
- %TEMP%\ish106125\css\sdk-ui\browse.css
- %TEMP%\ish106125\css\main.css
- %TEMP%\ish106125\css\sdk-ui\button.css
- %TEMP%\ish106125\css\sdk-ui\images\button-bg.png
- %TEMP%\ish106125\css\sdk-ui\checkbox.css
- %TEMP%\00019DC1.log
- %TEMP%\00019D54.log
- %TEMP%\ish106125\blank.gif
- %TEMP%\ish106125\css\ie6_main.css
- %TEMP%\ish106125\css\buttons.css
- %TEMP%\ish106125\images\back-button.png
- %TEMP%\ish106125\defaultOffer\US\offer_html.txt
- %TEMP%\ish106125\images\Bg.jpg
- %TEMP%\ish106125\images\finish-button.png
- %TEMP%\ish106125\images\close_button.png
- %TEMP%\ish106125\css\sdk-ui\progress-bar.css
- %TEMP%\ish106125\css\sdk-ui\images\progress-bg.png
- %TEMP%\ish106125\defaultOffer\offer_code.txt
- %TEMP%\ish106125\defaultOffer\US\offer_code.txt
- %TEMP%\ish106125\defaultOffer\offer_html.txt
- %PROGRAM_FILES%\is124031.log
- %TEMP%\0001E857.log
- %TEMP%\ish106125\bootstrap_60936.html
- %TEMP%\00019D54.log
- %TEMP%\00019DC1.log
- %TEMP%\0001DFDB.log
- 'cd###.solvefile.com':80
- 'rp.###vefile.com':80
- 'os.###vefile.com':80
- cd###.solvefile.com/Prod/VideoConverter-v2.cis
- os.###vefile.com/fx/v1.0.1/
- rp.###vefile.com/?pc#############
- DNS ASK cd###.solvefile.com
- DNS ASK rp.###vefile.com
- DNS ASK os.###vefile.com
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''