Technical Information
- [HKLM\SYSTEM\CurrentControlSet\Services\PrintManager] 'Start' = '00000002'
- [HKLM\SYSTEM\CurrentControlSet\Services\PrintManager] 'ImagePath' = '%ALLUSERSPROFILE%\PrintManager\PrintManager.exe'
- 'PrintManager' %ALLUSERSPROFILE%\PrintManager\PrintManager.exe
- %TEMP%\is-9ioup.tmp\<File name>.tmp
- %TEMP%\is-a6rv7.tmp\_isetup\_regdll.tmp
- %TEMP%\is-a6rv7.tmp\_isetup\_setup64.tmp
- %TEMP%\is-a6rv7.tmp\_isetup\_shfoldr.dll
- %TEMP%\is-a6rv7.tmp\_isetup\_isdecmp.dll
- %TEMP%\is-a6rv7.tmp\_isetup\_iscrypt.dll
- %TEMP%\is-a6rv7.tmp\is-5gjd1.tmp
- %TEMP%\is-a6rv7.tmp\is-1bauc.tmp
- %TEMP%\is-a6rv7.tmp\is-vnki9.tmp
- %TEMP%\is-a6rv7.tmp\is-srg84.tmp
- %TEMP%\is-a6rv7.tmp\liwflashfixsetup.exe
- %ALLUSERSPROFILE%\printmanager\printmanager.exe
- %TEMP%\is-9ioup.tmp\<File name>.tmp
- from %TEMP%\is-a6rv7.tmp\is-5gjd1.tmp to %TEMP%\is-a6rv7.tmp\liwflashfixsetup.exe
- from %TEMP%\is-a6rv7.tmp\is-1bauc.tmp to %TEMP%\is-a6rv7.tmp\downloader.exe
- from %TEMP%\is-a6rv7.tmp\is-vnki9.tmp to %TEMP%\is-a6rv7.tmp\yb.bmp
- from %TEMP%\is-a6rv7.tmp\is-srg84.tmp to %TEMP%\is-a6rv7.tmp\ya.bmp
- ClassName: '{2791D304-713B-2651-61B9-36EC194B7D52}' WindowName: ''
- '%TEMP%\is-9ioup.tmp\<File name>.tmp' /SL5="$70130,2419463,257024,<Full path to file>"
- '%TEMP%\is-a6rv7.tmp\liwflashfixsetup.exe'