Technical Information
- %LOCALAPPDATA%\google\chrome\user data\default\cookies
- %LOCALAPPDATA%\google\chrome\user data\default\login data
- %LOCALAPPDATA%\google\chrome\user data\default\web data
- %TEMP%\is-u17b6.tmp\<File name>.tmp
- %LOCALAPPDATA%\free photo slide show ultimate\is-485pc.tmp
- %ALLUSERSPROFILE%\vcruntime140.dll
- %ALLUSERSPROFILE%\softokn3.dll
- %ALLUSERSPROFILE%\nss3.dll
- %ALLUSERSPROFILE%\msvcp140.dll
- %ALLUSERSPROFILE%\mozglue.dll
- %ALLUSERSPROFILE%\freebl3.dll
- %ALLUSERSPROFILE%\48742792704664793018359284
- %ALLUSERSPROFILE%\48742792704664793018359284-shm
- %ALLUSERSPROFILE%\83507622830779295016438807
- %ALLUSERSPROFILE%\09051752074116959242449819
- %LOCALAPPDATA%\free photo slide show ultimate\is-ve90g.tmp
- %LOCALAPPDATA%\free photo slide show ultimate\is-gfl2u.tmp
- %ALLUSERSPROFILE%\09051752074116959242449819-shm
- %ALLUSERSPROFILE%\93122351610551632225096335
- %ALLUSERSPROFILE%\93122351610551632225096335-shm
- %ALLUSERSPROFILE%\30937944480216320306566469
- %ALLUSERSPROFILE%\17350588459536964301158229
- %ALLUSERSPROFILE%\41624400503073618510949259
- %ALLUSERSPROFILE%\37442908334002894940126721
- %ALLUSERSPROFILE%\52995128587541567088239834
- %ALLUSERSPROFILE%\78469350631089221215040874
- %ALLUSERSPROFILE%\31685334218180766930006291
- %ALLUSERSPROFILE%\31685334218180766930006291-shm
- %ALLUSERSPROFILE%\52977053492658696779393905
- %ALLUSERSPROFILE%\78659240467012068198285222
- %ALLUSERSPROFILE%\78659240467012068198285222-shm
- %LOCALAPPDATA%\free photo slide show ultimate\is-8qats.tmp
- %LOCALAPPDATA%\free photo slide show ultimate\is-t6d4j.tmp
- %LOCALAPPDATA%\free photo slide show ultimate\is-obdk6.tmp
- %LOCALAPPDATA%\free photo slide show ultimate\is-ln61t.tmp
- %LOCALAPPDATA%\free photo slide show ultimate\is-c1tfp.tmp
- %LOCALAPPDATA%\free photo slide show ultimate\is-3trmc.tmp
- %LOCALAPPDATA%\free photo slide show ultimate\is-2i7tj.tmp
- %LOCALAPPDATA%\free photo slide show ultimate\is-vhn0t.tmp
- %LOCALAPPDATA%\free photo slide show ultimate\firm\is-8m4dl.tmp
- %LOCALAPPDATA%\free photo slide show ultimate\is-hjoqm.tmp
- %LOCALAPPDATA%\free photo slide show ultimate\is-p2tu2.tmp
- %LOCALAPPDATA%\free photo slide show ultimate\is-9vqq6.tmp
- %LOCALAPPDATA%\free photo slide show ultimate\is-qp3v5.tmp
- %LOCALAPPDATA%\free photo slide show ultimate\is-h3lh5.tmp
- %LOCALAPPDATA%\free photo slide show ultimate\is-tm89h.tmp
- %TEMP%\is-7ttid.tmp\_isetup\_setup64.tmp
- %LOCALAPPDATA%\free photo slide show ultimate\is-aekqi.tmp
- %LOCALAPPDATA%\free photo slide show ultimate\is-b4mok.tmp
- %LOCALAPPDATA%\free photo slide show ultimate\is-bmnpp.tmp
- %LOCALAPPDATA%\free photo slide show ultimate\is-g4h2p.tmp
- %LOCALAPPDATA%\free photo slide show ultimate\is-pms02.tmp
- %LOCALAPPDATA%\free photo slide show ultimate\is-bdp3p.tmp
- %LOCALAPPDATA%\free photo slide show ultimate\is-p1jch.tmp
- %LOCALAPPDATA%\free photo slide show ultimate\is-99a7i.tmp
- %LOCALAPPDATA%\free photo slide show ultimate\is-du5r0.tmp
- %LOCALAPPDATA%\free photo slide show ultimate\is-026pc.tmp
- %LOCALAPPDATA%\free photo slide show ultimate\is-9663i.tmp
- %LOCALAPPDATA%\free photo slide show ultimate\is-g3fhm.tmp
- %LOCALAPPDATA%\free photo slide show ultimate\is-d870i.tmp
- %LOCALAPPDATA%\free photo slide show ultimate\is-9h541.tmp
- %ALLUSERSPROFILE%\78420194546195249817387916
- %ALLUSERSPROFILE%\78420194546195249817387916-shm
- %TEMP%\is-7ttid.tmp\_isetup\_setup64.tmp
- %ALLUSERSPROFILE%\52977053492658696779393905
- %ALLUSERSPROFILE%\31685334218180766930006291
- %ALLUSERSPROFILE%\31685334218180766930006291-shm
- %ALLUSERSPROFILE%\78469350631089221215040874
- %ALLUSERSPROFILE%\52995128587541567088239834
- %ALLUSERSPROFILE%\37442908334002894940126721
- %ALLUSERSPROFILE%\41624400503073618510949259
- %ALLUSERSPROFILE%\17350588459536964301158229
- %ALLUSERSPROFILE%\78420194546195249817387916-shm
- %ALLUSERSPROFILE%\93122351610551632225096335
- %ALLUSERSPROFILE%\78659240467012068198285222
- %ALLUSERSPROFILE%\78659240467012068198285222-shm
- %ALLUSERSPROFILE%\09051752074116959242449819
- %ALLUSERSPROFILE%\09051752074116959242449819-shm
- %ALLUSERSPROFILE%\83507622830779295016438807
- %ALLUSERSPROFILE%\48742792704664793018359284
- %ALLUSERSPROFILE%\48742792704664793018359284-shm
- %TEMP%\is-u17b6.tmp\<File name>.tmp
- %ALLUSERSPROFILE%\93122351610551632225096335-shm
- %ALLUSERSPROFILE%\78420194546195249817387916
- from %LOCALAPPDATA%\free photo slide show ultimate\is-ln61t.tmp to %LOCALAPPDATA%\free photo slide show ultimate\coreinfomgr.dll
- from %LOCALAPPDATA%\free photo slide show ultimate\is-ve90g.tmp to %LOCALAPPDATA%\free photo slide show ultimate\spanish.lng
- from %LOCALAPPDATA%\free photo slide show ultimate\is-8qats.tmp to %LOCALAPPDATA%\free photo slide show ultimate\russian.lng
- from %LOCALAPPDATA%\free photo slide show ultimate\is-t6d4j.tmp to %LOCALAPPDATA%\free photo slide show ultimate\readme.txt
- from %LOCALAPPDATA%\free photo slide show ultimate\is-obdk6.tmp to %LOCALAPPDATA%\free photo slide show ultimate\portuguese.lng
- from %LOCALAPPDATA%\free photo slide show ultimate\is-d870i.tmp to %LOCALAPPDATA%\free photo slide show ultimate\license.txt
- from %LOCALAPPDATA%\free photo slide show ultimate\is-g3fhm.tmp to %LOCALAPPDATA%\free photo slide show ultimate\korean.lng
- from %LOCALAPPDATA%\free photo slide show ultimate\is-9663i.tmp to %LOCALAPPDATA%\free photo slide show ultimate\japanese.lng
- from %LOCALAPPDATA%\free photo slide show ultimate\is-026pc.tmp to %LOCALAPPDATA%\free photo slide show ultimate\italian.lng
- from %LOCALAPPDATA%\free photo slide show ultimate\is-du5r0.tmp to %LOCALAPPDATA%\free photo slide show ultimate\ielib32.dll
- from %LOCALAPPDATA%\free photo slide show ultimate\is-99a7i.tmp to %LOCALAPPDATA%\free photo slide show ultimate\ielang32.dll
- from %LOCALAPPDATA%\free photo slide show ultimate\is-p1jch.tmp to %LOCALAPPDATA%\free photo slide show ultimate\german.lng
- from %LOCALAPPDATA%\free photo slide show ultimate\is-bdp3p.tmp to %LOCALAPPDATA%\free photo slide show ultimate\french.lng
- from %LOCALAPPDATA%\free photo slide show ultimate\is-pms02.tmp to %LOCALAPPDATA%\free photo slide show ultimate\freephotoslideshow.ico
- from %LOCALAPPDATA%\free photo slide show ultimate\is-g4h2p.tmp to %LOCALAPPDATA%\free photo slide show ultimate\freephotoslideshow.exe.manifest
- from %LOCALAPPDATA%\free photo slide show ultimate\is-bmnpp.tmp to %LOCALAPPDATA%\free photo slide show ultimate\freephotoslideshow.exe
- from %LOCALAPPDATA%\free photo slide show ultimate\is-b4mok.tmp to %LOCALAPPDATA%\free photo slide show ultimate\freephotoslideshow.chm
- from %LOCALAPPDATA%\free photo slide show ultimate\is-9h541.tmp to %LOCALAPPDATA%\free photo slide show ultimate\english.lng
- from %LOCALAPPDATA%\free photo slide show ultimate\is-aekqi.tmp to %LOCALAPPDATA%\free photo slide show ultimate\dutch.lng
- from %LOCALAPPDATA%\free photo slide show ultimate\is-tm89h.tmp to %LOCALAPPDATA%\free photo slide show ultimate\chinese.lng
- from %LOCALAPPDATA%\free photo slide show ultimate\is-h3lh5.tmp to %LOCALAPPDATA%\free photo slide show ultimate\back6.jpg
- from %LOCALAPPDATA%\free photo slide show ultimate\is-qp3v5.tmp to %LOCALAPPDATA%\free photo slide show ultimate\back5.jpg
- from %LOCALAPPDATA%\free photo slide show ultimate\is-9vqq6.tmp to %LOCALAPPDATA%\free photo slide show ultimate\back4.jpg
- from %LOCALAPPDATA%\free photo slide show ultimate\is-p2tu2.tmp to %LOCALAPPDATA%\free photo slide show ultimate\back3.jpg
- from %LOCALAPPDATA%\free photo slide show ultimate\is-hjoqm.tmp to %LOCALAPPDATA%\free photo slide show ultimate\back2.jpg
- from %LOCALAPPDATA%\free photo slide show ultimate\firm\is-8m4dl.tmp to %LOCALAPPDATA%\free photo slide show ultimate\firm\database.wav
- from %LOCALAPPDATA%\free photo slide show ultimate\is-vhn0t.tmp to %LOCALAPPDATA%\free photo slide show ultimate\mc_enc_mpa.dll
- from %LOCALAPPDATA%\free photo slide show ultimate\is-2i7tj.tmp to %LOCALAPPDATA%\free photo slide show ultimate\libwebp.dll
- from %LOCALAPPDATA%\free photo slide show ultimate\is-3trmc.tmp to %LOCALAPPDATA%\free photo slide show ultimate\fscapture.exe
- from %LOCALAPPDATA%\free photo slide show ultimate\is-c1tfp.tmp to %LOCALAPPDATA%\free photo slide show ultimate\efxtext.dll
- from %LOCALAPPDATA%\free photo slide show ultimate\is-gfl2u.tmp to %LOCALAPPDATA%\free photo slide show ultimate\turkish.lng
- from %LOCALAPPDATA%\free photo slide show ultimate\is-485pc.tmp to %LOCALAPPDATA%\free photo slide show ultimate\whatsnew_fpss.txt
- %ALLUSERSPROFILE%\78659240467012068198285222
- 't.#e':443
- 'st####ommunity.com':443
- '11#.#03.7.16':80
- http://11#.#03.7.16/5083892b57fd26cb0457d0b1d3cbb6f7
- http://11#.#03.7.16/htdocs.zip
- 't.#e':443
- 'st####ommunity.com':443
- DNS ASK t.#e
- DNS ASK st####ommunity.com
- '%TEMP%\is-u17b6.tmp\<File name>.tmp' /SL5="$F0172,9388025,832512,<Full path to file>"
- '%LOCALAPPDATA%\free photo slide show ultimate\fscapture.exe'