Technical Information
- %TEMP%\is-uvn5l.tmp\<File name>.tmp
- %TEMP%\is-phedo.tmp\_isetup\_setup64.tmp
- %TEMP%\is-phedo.tmp\_isetup\_shfoldr.dll
- %TEMP%\is-phedo.tmp\isfunclib.dll
- %TEMP%\is-phedo.tmp\bass.dll
- %TEMP%\is-phedo.tmp\eurostile.ttf
- %TEMP%\is-phedo.tmp\vclstylesinno.dll
- %TEMP%\is-phedo.tmp\d3dx9_43.dll
- %TEMP%\is-phedo.tmp\d3dx9_44.dll
- %TEMP%\is-gs2b0.cmd
- nul
- %TEMP%\is-gs2b0.cmd
- ClassName: 'DPWManager' WindowName: ''
- ClassName: 'WIN32_CLASS' WindowName: ''
- ClassName: 'Edit' WindowName: ''
- '%TEMP%\is-uvn5l.tmp\<File name>.tmp' /SL5="$E02E8,5255051,342016,<Full path to file>"
- '%TEMP%\is-phedo.tmp\d3dx9_44.dll'
- '<SYSTEM32>\cmd.exe' /C ""%TEMP%\is-GS2B0.cmd""
- '<SYSTEM32>\tasklist.exe' /FI "PID eq 5336"
- '<SYSTEM32>\find.exe' "5336"
- '<SYSTEM32>\ping.exe' 127.0.0.1 -n 1 -w 500
- '<SYSTEM32>\cmd.exe' /C ""%TEMP%\is-GS2B0.cmd""' (with hidden window)