Technical Information
- %TEMP%\~1346a0.~~~
- %WINDIR%\syswow64\t30600e.ini
- %WINDIR%\syswow64\rpcss.dll
- %WINDIR%\syswow64\t30600e.dll
- '%WINDIR%\syswow64\cmd.exe' /c <SYSTEM32>\rundll32.exe %TEMP%\~1346a0.~~~ GetName <Full path to file>
- '%WINDIR%\syswow64\rundll32.exe' %TEMP%\~1346a0.~~~ GetName <Full path to file>
- '%WINDIR%\syswow64\cmd.exe' /c <SYSTEM32>\rundll32.exe %TEMP%\~1346a0.~~~ GetName <Full path to file>' (with hidden window)