Technical Information
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'RuntimeBroker' = '%WINDIR%\RuntimeBroker.exe'
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'RuntimeBroker' = '%WINDIR%\RuntimeBroker.exe'
- %TEMP%\is-q6m1a.tmp\<File name>.tmp
- %TEMP%\is-2gbbg.tmp\_isetup\_setup64.tmp
- %TEMP%\is-kduii.tmp\<File name>.tmp
- %TEMP%\is-mn086.tmp\_isetup\_setup64.tmp
- %WINDIR%\is-irked.tmp
- %WINDIR%\is-maqbm.tmp
- %WINDIR%\is-sl4le.tmp
- %WINDIR%\unins000.dat
- %TEMP%\is-2gbbg.tmp\_isetup\_setup64.tmp
- %TEMP%\is-mn086.tmp\_isetup\_setup64.tmp
- %TEMP%\is-kduii.tmp\<File name>.tmp
- %TEMP%\is-q6m1a.tmp\<File name>.tmp
- from %WINDIR%\is-irked.tmp to %WINDIR%\unins000.exe
- from %WINDIR%\is-maqbm.tmp to %WINDIR%\planetapp.exe
- from %WINDIR%\is-sl4le.tmp to %WINDIR%\runtimebroker.exe
- '%TEMP%\is-q6m1a.tmp\<File name>.tmp' /SL5="$60246,5084301,1113600,<Full path to file>"
- '%TEMP%\is-kduii.tmp\<File name>.tmp' /SL5="$601BA,5084301,1113600,<Full path to file>" /VERYSILENT