Technical Information
- [<HKCU>\Software\Microsoft\Internet Explorer\Download] 'CheckExeSignatures' = 'no'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments] 'SaveZoneInformation' = '00000001'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Policies\Associations] 'LowRiskFileTypes' = '.zip;.rar;.nfo;.txt;.exe;.bat;.com;.cmd;.reg;.msi;.htm;.html;.gif;.bmp;.jpg;.avi;.mpg;.mpeg;.mov;....
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1601' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings] 'WarnOnZoneCrossing' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings] 'WarnonBadCertRecving' = '00000000'
- %HOMEPATH%\Desktop\Data_Recovery.lnk
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\Data_Recovery.lnk
- %HOMEPATH%\Start Menu\Programs\Data Recovery\Uninstall Data Recovery.lnk
- %ALLUSERSPROFILE%\Application Data\2yn_[+BjX{lR
- %HOMEPATH%\Start Menu\Programs\Data Recovery\Data Recovery.lnk
- from <Full path to file> to %ALLUSERSPROFILE%\Application Data\2yn_[+BjX{lR.exe
- 'sr###eptir.com':80
- 'ho###sinad.com':80
- 'xh###thexp.com':80
- 'la####uinesc.com':80
- 'li###clubin.com':80
- http://sr###eptir.com/support/s
- http://li###clubin.com/support/sr
- http://sr###eptir.com/support/sr
- http://ho###sinad.com/support/sr
- http://ho###sinad.com/support/s
- http://li###clubin.com/support/s
- http://li###clubin.com/s.php?0Q######################################################################
- http://la####uinesc.com/support/s
- http://la####uinesc.com/support/sr
- http://xh###thexp.com/support/sr
- http://xh###thexp.com/support/s
- DNS ASK sr###eptir.com
- DNS ASK ho###sinad.com
- DNS ASK xh###thexp.com
- DNS ASK la####uinesc.com
- DNS ASK li###clubin.com
- ClassName: 'Shell_TrayWnd' WindowName: ''