Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] '%WINDIR%\explorer.exe' = '%WINDIR%\explorer.exe:*:Enabled:Windows Shell'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '%WINDIR%\explorer.exe' = '%WINDIR%\explorer.exe:*:Enabled:Windows Shell'
- '<SYSTEM32>\netsh.exe' firewall add allowedprogram program="%WINDIR%\explorer.exe" name="Windows Shell" mode=ENABLE scope=ALL profile=ALL
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\CA63GXYV.txt
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\CAL4WBPH.txt
- <SYSTEM32>\dmutil32.dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\CAGQG7BP.txt
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\CAL4WBPH.txt
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\CA63GXYV.txt
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\CAGQG7BP.txt
- '89.##9.242.187':80
- '78.##9.122.102':80
- 'localhost':1038
- '18#.#2.250.35':80