Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Windows Setup API' = '"<Full path to file>"'
- '%TEMP%\is-GI40K.tmp\3037576.tjrzi1r3ViaRu.tmp' /SL5="$100E2,2383724,67072,%TEMP%\3037576.tjrzi1r3ViaRu.exe"
- '%WINDIR%\Microsoft.NET\Framework\v2.0.50727\vbc.exe'
- '%WINDIR%\Microsoft.NET\Framework\v2.0.50727\InstallUtil.exe' /logtoconsole=false /logfile= /u "<Full path to file>"
- '%TEMP%\3037576.tjrzi1r3ViaRu.exe'
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\vbc.exe
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\.Identifier
- %TEMP%\3037576.tjrzi1r3ViaRu.exe
- %HOMEPATH%\Setup API\WmiPrvSE.EXE
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\.Identifier
- '85.##.184.183':33360
- 'wp#d':80
- http://11#.#11.111.1/wpad.dat via wp#d
- DNS ASK wp#d
- ClassName: 'Edit' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''