Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '<Full path to file>' = '<Full path to file>:*:Enabled:File and Printer...
- ClassName: 'OLLYDBG', WindowName: ''
- %TEMP%\evb8.tmp
- %TEMP%\evb7.tmp
- %TEMP%\evbA.tmp
- %TEMP%\evb9.tmp
- %TEMP%\evb6.tmp
- %TEMP%\evb3.tmp
- %TEMP%\evb2.tmp
- %TEMP%\evb5.tmp
- %TEMP%\evb4.tmp
- 'pa##.#ame4you.us':80
- 'wp#d':80
- http://pa##.#ame4you.us/GetPathInfo.aspx?Ve#######
- http://11#.#11.111.1/wpad.dat via wp#d
- DNS ASK pa##.#ame4you.us
- DNS ASK wp#d