Thanks Jax,
Have now added the URL for harvesting
Ps now i know why i dont take time off

...was my first day(s) off since end of May and boy has it stacked up
Hey this is turning out to be a fun rabbit hole,the first file you linked up is a configuration file and is none PE..but it had a URL in the HEX
http://61.235.117.83/popup.php
Went there and get hit with fake scanner redirect
http://securitytestnetonline.com/download.php?affid=12410
Can see how these nets work by spreading packaged droppers...Malware affialites
Woot i is back and on fire