Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'MicroUpdate' = '%TEMP%\MSDCSC\msdcsc.exe'
- [<HKLM>\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] 'UserInit' = '<SYSTEM32>\userinit.exe,%TEMP%\MSDCSC\msdcsc.exe'
- %TEMP%\msmngr.exe
- %TEMP%\7zipsfx.000\t\mui\nb-no\systemcpl.dll.mui
- %TEMP%\7zipsfx.000\t\mui\lt-lt\systemcpl.dll.mui
- %TEMP%\7zipsfx.000\t\mui\th-th\systemcpl.dll.mui
- %TEMP%\7zipsfx.000\t\mui\es-es\systemcpl.dll.mui
- %TEMP%\7zipsfx.000\t\mui\fr-fr\systemcpl.dll.mui
- %TEMP%\7zipsfx.000\t\mui\sv-se\systemcpl.dll.mui
- %TEMP%\7zipsfx.000\t\mui\zh-hk\systemcpl.dll.mui
- %TEMP%\7zipsfx.000\t\mui\et-ee\systemcpl.dll.mui
- %TEMP%\7zipsfx.000\t\mui\el-gr\systemcpl.dll.mui
- %TEMP%\7zipsfx.000\t\mui\ja-jp\systemcpl.dll.mui
- %TEMP%\7zipsfx.000\t\mui\en-us\systemcpl.dll.mui
- %TEMP%\7zipsfx.000\t\mui\zh-tw\systemsettings.exe.mui
- %TEMP%\7zipsfx.000\t\mui\ro-ro\systemsettings.exe.mui
- %TEMP%\7zipsfx.000\t\mui\sk-sk\systemsettings.exe.mui
- %TEMP%\7zipsfx.000\t\mui\tr-tr\systemsettings.exe.mui
- %TEMP%\7zipsfx.000\t\mui\en-gb\systemcpl.dll.mui
- %TEMP%\7zipsfx.000\t\mui\ko-kr\systemcpl.dll.mui
- %TEMP%\7zipsfx.000\t\mui\sl-si\systemsettings.exe.mui
- %TEMP%\7zipsfx.000\t\mui\fi-fi\systemsettings.exe.mui
- %TEMP%\7zipsfx.000\t\mui\ru-ru\systemcpl.dll.mui
- %TEMP%\7zipsfx.000\t\mui\pl-pl\systemcpl.dll.mui
- %TEMP%\7zipsfx.000\t\mui\pt-pt\systemcpl.dll.mui
- %TEMP%\7zipsfx.000\t\mui\lv-lv\systemcpl.dll.mui
- %TEMP%\7zipsfx.000\t\mui\pt-br\systemcpl.dll.mui
- %TEMP%\7zipsfx.000\t\mui\de-de\systemcpl.dll.mui
- %TEMP%\7zipsfx.000\t\mui\zh-cn\systemcpl.dll.mui
- %TEMP%\7zipsfx.000\t\mui\sk-sk\systemcpl.dll.mui
- %TEMP%\7zipsfx.000\t\mui\uk-ua\systemcpl.dll.mui
- %TEMP%\7zipsfx.000\t\mui\da-dk\systemcpl.dll.mui
- %TEMP%\7zipsfx.000\t\mui\it-it\systemcpl.dll.mui
- %TEMP%\7zipsfx.000\t\mui\ar-sa\systemcpl.dll.mui
- %TEMP%\7zipsfx.000\t\mui\hu-hu\systemcpl.dll.mui
- %TEMP%\7zipsfx.000\t\mui\hr-hr\systemcpl.dll.mui
- %TEMP%\7zipsfx.000\t\mui\nl-nl\systemcpl.dll.mui
- %TEMP%\7zipsfx.000\t\mui\cs-cz\systemcpl.dll.mui
- %TEMP%\7zipsfx.000\t\mui\bg-bg\systemcpl.dll.mui
- %TEMP%\7zipsfx.000\t\mui\he-il\systemcpl.dll.mui
- %TEMP%\7zipsfx.000\t\mui\fr-fr\actioncenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\pl-pl\systemsettings.exe.mui
- %TEMP%\7zipsfx.000\t\mui\sv-se\systemsettings.exe.mui
- %TEMP%\7zipsfx.000\t\mui\en-gb\systemsettings.exe.mui
- %TEMP%\7zipsfx.000\t\mui\zh-cn\systemsettings.exe.mui
- %TEMP%\7zipsfx.000\t\mui\fr-fr\systemsettings.exe.mui
- %TEMP%\7zipsfx.000\t\mui\ja-jp\systemsettings.exe.mui
- %TEMP%\7zipsfx.000\t\mui\en-us\systemsettings.exe.mui
- %TEMP%\7zipsfx.000\t\mui\ko-kr\systemsettings.exe.mui
- %TEMP%\msdcsc\msdcsc.exe
- %TEMP%\7zipsfx.000\t\mui\el-gr\systemsettings.exe.mui
- %TEMP%\7zipsfx.000\t\x86\actioncentercpl.dll
- %TEMP%\7zipsfx.000\t\x86\genuinecenter.dll
- %TEMP%\7zipsfx.000\t\x64\slchook.dll
- %TEMP%\7zipsfx.000\t\x86\slchook.dll
- %TEMP%\7zipsfx.000\t\x86\slwga.dll
- %TEMP%\7zipsfx.000\t\x64\slwga.dll
- %TEMP%\7zipsfx.000\t\x64\actioncentercpl.dll
- %TEMP%\7zipsfx.000\t\mui\es-es\systemsettings.exe.mui
- %TEMP%\7zipsfx.000\t\x64\genuinecenter.dll
- %TEMP%\7zipsfx.000\t\mui\th-th\systemsettings.exe.mui
- %TEMP%\7zipsfx.000\t\mui\lt-lt\systemsettings.exe.mui
- %TEMP%\7zipsfx.000\t\mui\lv-lv\systemsettings.exe.mui
- %TEMP%\7zipsfx.000\t\mui\de-de\systemsettings.exe.mui
- %TEMP%\7zipsfx.000\t\mui\da-dk\systemsettings.exe.mui
- %TEMP%\7zipsfx.000\t\mui\cs-cz\systemsettings.exe.mui
- %TEMP%\7zipsfx.000\t\mui\bg-bg\systemsettings.exe.mui
- %TEMP%\7zipsfx.000\t\mui\he-il\systemsettings.exe.mui
- %TEMP%\7zipsfx.000\t\mui\it-it\systemsettings.exe.mui
- %TEMP%\7zipsfx.000\t\mui\ar-sa\systemsettings.exe.mui
- %TEMP%\7zipsfx.000\t\mui\pt-br\systemsettings.exe.mui
- %TEMP%\7zipsfx.000\t\mui\hu-hu\systemsettings.exe.mui
- %TEMP%\7zipsfx.000\t\mui\nl-nl\systemsettings.exe.mui
- %TEMP%\7zipsfx.000\t\mui\ru-ru\systemsettings.exe.mui
- %TEMP%\7zipsfx.000\t\mui\uk-ua\systemsettings.exe.mui
- %TEMP%\7zipsfx.000\t\mui\et-ee\systemsettings.exe.mui
- %TEMP%\7zipsfx.000\t\mui\nb-no\systemsettings.exe.mui
- %TEMP%\7zipsfx.000\t\mui\zh-hk\systemsettings.exe.mui
- %TEMP%\7zipsfx.000\t\mui\fi-fi\systemcpl.dll.mui
- %TEMP%\7zipsfx.000\t\mui\hr-hr\systemsettings.exe.mui
- %TEMP%\7zipsfx.000\t\mui\sl-si\systemcpl.dll.mui
- %TEMP%\7zipsfx.000\t\mui\tr-tr\systemcpl.dll.mui
- %TEMP%\7zipsfx.000\t\mui\ro-ro\systemcpl.dll.mui
- %TEMP%\7zipsfx.000\t\mui\zh-tw\systemcpl.dll.mui
- %TEMP%\7zipsfx.000\t\mui\hu-hu\actioncenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\hr-hr\actioncenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\nl-nl\actioncenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\ru-ru\actioncenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\uk-ua\actioncenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\he-il\actioncenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\cs-cz\actioncenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\ar-sa\actioncenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\et-ee\actioncenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\th-th\actioncenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\es-es\actioncenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\ko-kr\actioncenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\sv-se\actioncenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\el-gr\actioncenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\nb-no\actioncenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\lt-lt\actioncenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\zh-hk\actioncenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\bg-bg\actioncenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\da-dk\actioncenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\en-gb\actioncenter.dll.mui
- %TEMP%\7zipsfx.000\ac.cmd
- %TEMP%\7zipsfx.000\install.cmd
- %TEMP%\7zipsfx.000\t\x64\slmgr.vbs
- %TEMP%\7zipsfx.000\t\x86\slmgr.vbs
- %TEMP%\7zipsfx.000\t\activation.reg
- %TEMP%\7zipsfx.000\t\mui\zh-tw\actioncenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\ro-ro\actioncenter.dll.mui
- %TEMP%\p8_v25.exe
- %TEMP%\7zipsfx.000\t\mui\fi-fi\actioncenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\sk-sk\actioncenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\sl-si\actioncenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\pl-pl\actioncenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\pt-pt\actioncenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\lv-lv\actioncenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\pt-br\actioncenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\de-de\actioncenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\tr-tr\actioncenter.dll.mui
- %TEMP%\7zipsfx.000\t\x86\windows.ui.immersive.dll
- %TEMP%\7zipsfx.000\t\mui\pt-pt\systemsettings.exe.mui
- %TEMP%\7zipsfx.000\t\mui\zh-cn\actioncenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\zh-tw\genuinecenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\zh-hk\genuinecenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\en-gb\genuinecenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\ko-kr\genuinecenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\uk-ua\genuinecenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\nl-nl\genuinecenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\sv-se\genuinecenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\hr-hr\genuinecenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\lv-lv\genuinecenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\hu-hu\genuinecenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\fi-fi\genuinecenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\fr-fr\genuinecenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\zh-cn\genuinecenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\ja-jp\genuinecenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\en-us\genuinecenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\lt-lt\genuinecenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\it-it\actioncenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\el-gr\genuinecenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\da-dk\genuinecenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\th-th\genuinecenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\bg-bg\genuinecenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\nb-no\genuinecenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\ar-sa\genuinecenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\de-de\genuinecenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\sk-sk\genuinecenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\sl-si\genuinecenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\et-ee\genuinecenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\en-us\actioncenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\it-it\genuinecenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\pt-br\genuinecenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\pt-pt\genuinecenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\ru-ru\genuinecenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\cs-cz\genuinecenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\es-es\genuinecenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\tr-tr\genuinecenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\pl-pl\genuinecenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\he-il\genuinecenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\ro-ro\genuinecenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\ja-jp\actioncenter.dll.mui
- %TEMP%\7zipsfx.000\t\x64\windows.ui.immersive.dll
- %TEMP%\7zipsfx.000\ac.cmd
- %TEMP%\7zipsfx.000\t\mui\pt-pt\systemcpl.dll.mui
- %TEMP%\7zipsfx.000\t\mui\pt-pt\systemsettings.exe.mui
- %TEMP%\7zipsfx.000\t\mui\ro-ro\actioncenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\ro-ro\genuinecenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\ro-ro\systemcpl.dll.mui
- %TEMP%\7zipsfx.000\t\mui\ro-ro\systemsettings.exe.mui
- %TEMP%\7zipsfx.000\t\mui\ru-ru\actioncenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\ru-ru\systemcpl.dll.mui
- %TEMP%\7zipsfx.000\t\mui\sl-si\systemcpl.dll.mui
- %TEMP%\7zipsfx.000\t\mui\ru-ru\systemsettings.exe.mui
- %TEMP%\7zipsfx.000\t\mui\sk-sk\actioncenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\sk-sk\genuinecenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\sk-sk\systemcpl.dll.mui
- %TEMP%\7zipsfx.000\t\mui\sk-sk\systemsettings.exe.mui
- %TEMP%\7zipsfx.000\t\mui\sl-si\actioncenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\sl-si\genuinecenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\pt-pt\genuinecenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\ru-ru\genuinecenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\pt-pt\actioncenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\nl-nl\genuinecenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\lv-lv\systemcpl.dll.mui
- %TEMP%\7zipsfx.000\t\mui\lv-lv\systemsettings.exe.mui
- %TEMP%\7zipsfx.000\t\mui\nb-no\actioncenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\nb-no\genuinecenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\nb-no\systemcpl.dll.mui
- %TEMP%\7zipsfx.000\t\mui\nb-no\systemsettings.exe.mui
- %TEMP%\7zipsfx.000\t\mui\nl-nl\actioncenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\nl-nl\systemcpl.dll.mui
- %TEMP%\7zipsfx.000\t\mui\pt-br\systemcpl.dll.mui
- %TEMP%\7zipsfx.000\t\mui\nl-nl\systemsettings.exe.mui
- %TEMP%\7zipsfx.000\t\mui\pl-pl\actioncenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\pl-pl\genuinecenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\pl-pl\systemcpl.dll.mui
- %TEMP%\7zipsfx.000\t\mui\pl-pl\systemsettings.exe.mui
- %TEMP%\7zipsfx.000\t\mui\pt-br\actioncenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\pt-br\genuinecenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\pt-br\systemsettings.exe.mui
- %TEMP%\7zipsfx.000\t\mui\tr-tr\systemcpl.dll.mui
- %TEMP%\7zipsfx.000\t\x86\slwga.dll
- %TEMP%\7zipsfx.000\t\mui\sv-se\genuinecenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\zh-hk\systemcpl.dll.mui
- %TEMP%\7zipsfx.000\t\mui\zh-hk\systemsettings.exe.mui
- %TEMP%\7zipsfx.000\t\mui\zh-tw\actioncenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\zh-tw\genuinecenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\zh-tw\systemcpl.dll.mui
- %TEMP%\7zipsfx.000\t\mui\zh-tw\systemsettings.exe.mui
- %TEMP%\7zipsfx.000\t\x64\actioncentercpl.dll
- %TEMP%\7zipsfx.000\t\x64\slchook.dll
- %TEMP%\7zipsfx.000\t\mui\sv-se\actioncenter.dll.mui
- %TEMP%\7zipsfx.000\t\x64\slmgr.vbs
- %TEMP%\7zipsfx.000\t\x64\slwga.dll
- %TEMP%\7zipsfx.000\t\x64\windows.ui.immersive.dll
- %TEMP%\7zipsfx.000\t\x86\actioncentercpl.dll
- %TEMP%\7zipsfx.000\t\x86\genuinecenter.dll
- %TEMP%\7zipsfx.000\t\x86\slchook.dll
- %TEMP%\7zipsfx.000\t\x86\slmgr.vbs
- %TEMP%\7zipsfx.000\t\mui\zh-hk\genuinecenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\lv-lv\genuinecenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\zh-hk\actioncenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\tr-tr\genuinecenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\sv-se\systemcpl.dll.mui
- %TEMP%\7zipsfx.000\t\mui\sv-se\systemsettings.exe.mui
- %TEMP%\7zipsfx.000\t\mui\th-th\actioncenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\th-th\genuinecenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\th-th\systemcpl.dll.mui
- %TEMP%\7zipsfx.000\t\mui\th-th\systemsettings.exe.mui
- %TEMP%\7zipsfx.000\t\mui\tr-tr\actioncenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\sl-si\systemsettings.exe.mui
- %TEMP%\7zipsfx.000\t\mui\zh-cn\systemcpl.dll.mui
- %TEMP%\7zipsfx.000\t\mui\tr-tr\systemsettings.exe.mui
- %TEMP%\7zipsfx.000\t\mui\uk-ua\actioncenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\uk-ua\genuinecenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\uk-ua\systemcpl.dll.mui
- %TEMP%\7zipsfx.000\t\mui\uk-ua\systemsettings.exe.mui
- %TEMP%\7zipsfx.000\t\mui\zh-cn\actioncenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\zh-cn\genuinecenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\zh-cn\systemsettings.exe.mui
- %TEMP%\7zipsfx.000\t\x64\genuinecenter.dll
- %TEMP%\7zipsfx.000\t\mui\lv-lv\actioncenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\ja-jp\genuinecenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\de-de\systemcpl.dll.mui
- %TEMP%\7zipsfx.000\t\mui\de-de\systemsettings.exe.mui
- %TEMP%\7zipsfx.000\t\mui\el-gr\actioncenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\el-gr\genuinecenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\el-gr\systemcpl.dll.mui
- %TEMP%\7zipsfx.000\t\mui\el-gr\systemsettings.exe.mui
- %TEMP%\7zipsfx.000\t\mui\en-gb\actioncenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\en-gb\systemcpl.dll.mui
- %TEMP%\7zipsfx.000\t\mui\es-es\systemcpl.dll.mui
- %TEMP%\7zipsfx.000\t\mui\en-gb\systemsettings.exe.mui
- %TEMP%\7zipsfx.000\t\mui\en-us\actioncenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\en-us\genuinecenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\en-us\systemcpl.dll.mui
- %TEMP%\7zipsfx.000\t\mui\en-us\systemsettings.exe.mui
- %TEMP%\7zipsfx.000\t\mui\es-es\actioncenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\es-es\genuinecenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\de-de\genuinecenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\en-gb\genuinecenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\de-de\actioncenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\bg-bg\genuinecenter.dll.mui
- %TEMP%\7zipsfx.000\install.cmd
- %TEMP%\7zipsfx.000\t\activation.reg
- %TEMP%\7zipsfx.000\t\mui\ar-sa\actioncenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\ar-sa\genuinecenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\ar-sa\systemcpl.dll.mui
- %TEMP%\7zipsfx.000\t\mui\ar-sa\systemsettings.exe.mui
- %TEMP%\7zipsfx.000\t\mui\bg-bg\actioncenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\bg-bg\systemcpl.dll.mui
- %TEMP%\7zipsfx.000\t\mui\da-dk\systemcpl.dll.mui
- %TEMP%\7zipsfx.000\t\mui\bg-bg\systemsettings.exe.mui
- %TEMP%\7zipsfx.000\t\mui\cs-cz\actioncenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\cs-cz\genuinecenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\cs-cz\systemcpl.dll.mui
- %TEMP%\7zipsfx.000\t\mui\cs-cz\systemsettings.exe.mui
- %TEMP%\7zipsfx.000\t\mui\da-dk\actioncenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\da-dk\genuinecenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\da-dk\systemsettings.exe.mui
- %TEMP%\7zipsfx.000\t\mui\fr-fr\systemcpl.dll.mui
- %TEMP%\7zipsfx.000\t\mui\lt-lt\systemcpl.dll.mui
- %TEMP%\7zipsfx.000\t\mui\et-ee\genuinecenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\hu-hu\systemcpl.dll.mui
- %TEMP%\7zipsfx.000\t\mui\hu-hu\systemsettings.exe.mui
- %TEMP%\7zipsfx.000\t\mui\it-it\actioncenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\it-it\genuinecenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\it-it\systemcpl.dll.mui
- %TEMP%\7zipsfx.000\t\mui\it-it\systemsettings.exe.mui
- %TEMP%\7zipsfx.000\t\mui\ja-jp\actioncenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\ja-jp\systemcpl.dll.mui
- %TEMP%\7zipsfx.000\t\mui\et-ee\actioncenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\ja-jp\systemsettings.exe.mui
- %TEMP%\7zipsfx.000\t\mui\ko-kr\actioncenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\ko-kr\genuinecenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\ko-kr\systemcpl.dll.mui
- %TEMP%\7zipsfx.000\t\mui\ko-kr\systemsettings.exe.mui
- %TEMP%\7zipsfx.000\t\mui\lt-lt\actioncenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\lt-lt\genuinecenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\hu-hu\genuinecenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\lt-lt\systemsettings.exe.mui
- %TEMP%\7zipsfx.000\t\mui\hu-hu\actioncenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\fr-fr\genuinecenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\et-ee\systemcpl.dll.mui
- %TEMP%\7zipsfx.000\t\mui\et-ee\systemsettings.exe.mui
- %TEMP%\7zipsfx.000\t\mui\fi-fi\actioncenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\fi-fi\genuinecenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\fi-fi\systemcpl.dll.mui
- %TEMP%\7zipsfx.000\t\mui\fi-fi\systemsettings.exe.mui
- %TEMP%\7zipsfx.000\t\mui\fr-fr\actioncenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\es-es\systemsettings.exe.mui
- %TEMP%\7zipsfx.000\t\mui\hr-hr\systemcpl.dll.mui
- %TEMP%\7zipsfx.000\t\mui\fr-fr\systemsettings.exe.mui
- %TEMP%\7zipsfx.000\t\mui\he-il\actioncenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\he-il\genuinecenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\he-il\systemcpl.dll.mui
- %TEMP%\7zipsfx.000\t\mui\he-il\systemsettings.exe.mui
- %TEMP%\7zipsfx.000\t\mui\hr-hr\actioncenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\hr-hr\genuinecenter.dll.mui
- %TEMP%\7zipsfx.000\t\mui\hr-hr\systemsettings.exe.mui
- %TEMP%\7zipsfx.000\t\x86\windows.ui.immersive.dll
- 'localhost':1604
- '17#.#37.139.118':1604
- DNS ASK ou###.no-ip.info
- '%TEMP%\msmngr.exe'
- '%TEMP%\p8_v25.exe'
- '%TEMP%\msdcsc\msdcsc.exe'
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\7ZipSfx.000\Install.cmd" "
- '<SYSTEM32>\reg.exe' QUERY "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion" /v "BuildLab"
- '%WINDIR%\syswow64\findstr.exe' /I "9200"