Technical Information
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce] 'GrpConv' = 'grpconv -o'
- %TEMP%\rarsfx0\setups.ini
- %WINDIR%\syswow64\set450f.tmp
- %WINDIR%\syswow64\set4520.tmp
- %WINDIR%\syswow64\set4530.tmp
- %WINDIR%\syswow64\set4550.tmp
- %WINDIR%\syswow64\set459f.tmp
- %WINDIR%\syswow64\set4452.tmp
- %WINDIR%\syswow64\set44a1.tmp
- %WINDIR%\syswow64\set45c0.tmp
- %WINDIR%\syswow64\set464f.tmp
- %WINDIR%\syswow64\set4660.tmp
- %WINDIR%\syswow64\set4680.tmp
- %WINDIR%\syswow64\set46a0.tmp
- %WINDIR%\syswow64\set46ff.tmp
- %WINDIR%\syswow64\set460f.tmp
- %WINDIR%\syswow64\set463e.tmp
- %WINDIR%\syswow64\set43f3.tmp
- %WINDIR%\syswow64\set43b4.tmp
- %WINDIR%\syswow64\set4394.tmp
- %WINDIR%\system\set41a2.tmp
- %WINDIR%\system\set41c2.tmp
- %WINDIR%\system\set41f2.tmp
- %WINDIR%\system\set4212.tmp
- %WINDIR%\system\set4232.tmp
- %WINDIR%\syswow64\set4243.tmp
- %WINDIR%\system\set4172.tmp
- %WINDIR%\syswow64\set4263.tmp
- %WINDIR%\syswow64\set4284.tmp
- %WINDIR%\syswow64\set4295.tmp
- %WINDIR%\syswow64\set42c5.tmp
- %WINDIR%\syswow64\set42e5.tmp
- %WINDIR%\syswow64\set4305.tmp
- %WINDIR%\syswow64\set4383.tmp
- %WINDIR%\syswow64\set4274.tmp
- %WINDIR%\syswow64\set472e.tmp
- %WINDIR%\syswow64\set474f.tmp
- %WINDIR%\syswow64\set477e.tmp
- %WINDIR%\syswow64\set479f.tmp
- %WINDIR%\syswow64\set4a61.tmp
- %WINDIR%\syswow64\set4a81.tmp
- %WINDIR%\syswow64\set4aa1.tmp
- %WINDIR%\syswow64\set4ac2.tmp
- %WINDIR%\syswow64\set4b01.tmp
- %WINDIR%\syswow64\set4b31.tmp
- %WINDIR%\syswow64\set4b51.tmp
- %WINDIR%\syswow64\set4b71.tmp
- %WINDIR%\syswow64\set4b91.tmp
- %WINDIR%\syswow64\set4bb2.tmp
- %WINDIR%\syswow64\set4be1.tmp
- %WINDIR%\syswow64\set4c02.tmp
- %WINDIR%\syswow64\set4c31.tmp
- %WINDIR%\syswow64\set4c42.tmp
- %WINDIR%\syswow64\set4c72.tmp
- %WINDIR%\syswow64\set4a31.tmp
- %WINDIR%\syswow64\set49f1.tmp
- %WINDIR%\syswow64\set4a11.tmp
- %WINDIR%\syswow64\set49e0.tmp
- %WINDIR%\syswow64\set47af.tmp
- %WINDIR%\syswow64\set47c0.tmp
- %WINDIR%\syswow64\set47e0.tmp
- %WINDIR%\syswow64\set4810.tmp
- %WINDIR%\syswow64\set4830.tmp
- %WINDIR%\syswow64\set4850.tmp
- %WINDIR%\syswow64\set4861.tmp
- %WINDIR%\syswow64\set4881.tmp
- %WINDIR%\syswow64\set48a1.tmp
- %WINDIR%\syswow64\set490f.tmp
- %WINDIR%\syswow64\set493f.tmp
- %WINDIR%\syswow64\set495f.tmp
- %WINDIR%\syswow64\set4980.tmp
- %WINDIR%\syswow64\set49a0.tmp
- %WINDIR%\syswow64\set49c0.tmp
- %WINDIR%\syswow64\set4c92.tmp
- %TEMP%\rarsfx0\i386\tabctl32.ocx
- %TEMP%\rarsfx0\i386\sysinfo.ocx
- %TEMP%\rarsfx0\i386\richtx32.ocx
- %TEMP%\rarsfx0\i386\mfc70ita.dll
- %TEMP%\rarsfx0\i386\mfc70jpn.dll
- %TEMP%\rarsfx0\i386\mfc70kor.dll
- %TEMP%\rarsfx0\i386\mfc70u.dll
- %TEMP%\rarsfx0\i386\mfc71.dll
- %TEMP%\rarsfx0\i386\mfc70esp.dll
- %TEMP%\rarsfx0\i386\mfc70fra.dll
- %TEMP%\rarsfx0\i386\mfc71chs.dll
- %TEMP%\rarsfx0\i386\mfc71enu.dll
- %TEMP%\rarsfx0\i386\mfc71esp.dll
- %TEMP%\rarsfx0\i386\mfc71fra.dll
- %TEMP%\rarsfx0\i386\mfc71ita.dll
- %TEMP%\rarsfx0\i386\mfc71jpn.dll
- %TEMP%\rarsfx0\i386\mfc71cht.dll
- %TEMP%\rarsfx0\i386\mfc71deu.dll
- %TEMP%\rarsfx0\i386\mfc70enu.dll
- %TEMP%\rarsfx0\i386\mfc70deu.dll
- %TEMP%\rarsfx0\i386\mfc70cht.dll
- %TEMP%\rarsfx0\setups.exe
- %TEMP%\rarsfx0\i386\atl70.dll
- %TEMP%\rarsfx0\i386\atl71.dll
- %TEMP%\rarsfx0\i386\autoitx3.dll
- %TEMP%\rarsfx0\i386\cygwin1.dll
- %TEMP%\rarsfx0\i386\cygwinb19.dll
- %TEMP%\rarsfx0\runtimes.inf
- %TEMP%\rarsfx0\i386\libeay32.dll
- %TEMP%\rarsfx0\i386\libintl3.dll
- %TEMP%\rarsfx0\i386\libmmd.dll
- %TEMP%\rarsfx0\i386\libpng13.dll
- %TEMP%\rarsfx0\i386\libssl32.dll
- %TEMP%\rarsfx0\i386\mfc70.dll
- %TEMP%\rarsfx0\i386\mfc70chs.dll
- %TEMP%\rarsfx0\i386\libiconv2.dll
- %TEMP%\rarsfx0\i386\mfc71kor.dll
- %TEMP%\rarsfx0\i386\mfc71u.dll
- %TEMP%\rarsfx0\i386\msstdfmt.dll
- %TEMP%\rarsfx0\i386\msstkprp.dll
- %TEMP%\rarsfx0\i386\comctl32.ocx
- %TEMP%\rarsfx0\i386\comdlg32.ocx
- %TEMP%\rarsfx0\i386\dblist32.ocx
- %TEMP%\rarsfx0\i386\mci32.ocx
- %TEMP%\rarsfx0\i386\mscomct2.ocx
- %TEMP%\rarsfx0\i386\mscomctl.ocx
- %TEMP%\rarsfx0\i386\mscomctl32.ocx
- %TEMP%\rarsfx0\i386\mscomm32.ocx
- %TEMP%\rarsfx0\i386\msdatgrd.ocx
- %TEMP%\rarsfx0\i386\msdatlst.ocx
- %TEMP%\rarsfx0\i386\msflxgrd.ocx
- %TEMP%\rarsfx0\i386\mshflxgd.ocx
- %TEMP%\rarsfx0\i386\msinet.ocx
- %TEMP%\rarsfx0\i386\msmask32.ocx
- %TEMP%\rarsfx0\i386\mswinsck.ocx
- %TEMP%\rarsfx0\i386\comct332.ocx
- %TEMP%\rarsfx0\icon.ico
- %TEMP%\rarsfx0\i386\comct232.ocx
- %TEMP%\rarsfx0\i386\zlib1.dll
- %TEMP%\rarsfx0\i386\msvci70.dll
- %TEMP%\rarsfx0\i386\msvcp70.dll
- %TEMP%\rarsfx0\i386\msvcp71.dll
- %TEMP%\rarsfx0\i386\msvcr70.dll
- %TEMP%\rarsfx0\i386\msvcr71.dll
- %TEMP%\rarsfx0\i386\msvcrt10.dll
- %TEMP%\rarsfx0\i386\openal32.dll
- %TEMP%\rarsfx0\i386\plugin.dll
- %TEMP%\rarsfx0\i386\ssleay32.dll
- %TEMP%\rarsfx0\i386\vb40016.dll
- %TEMP%\rarsfx0\i386\vb40032.dll
- %TEMP%\rarsfx0\i386\vbrun100.dll
- %TEMP%\rarsfx0\i386\vbrun200.dll
- %TEMP%\rarsfx0\i386\vbrun300.dll
- %TEMP%\rarsfx0\i386\wrap_oal.dll
- %TEMP%\rarsfx0\i386\picclp32.ocx
- %TEMP%\setups.reg
- %TEMP%\rarsfx0\icon.ico
- %TEMP%\rarsfx0\i386\msvci70.dll
- %TEMP%\rarsfx0\i386\msstkprp.dll
- %TEMP%\rarsfx0\i386\msstdfmt.dll
- %TEMP%\rarsfx0\i386\msmask32.ocx
- %TEMP%\rarsfx0\i386\msinet.ocx
- %TEMP%\rarsfx0\i386\mshflxgd.ocx
- %TEMP%\rarsfx0\i386\msflxgrd.ocx
- %TEMP%\rarsfx0\i386\msdatlst.ocx
- %TEMP%\rarsfx0\i386\msdatgrd.ocx
- %TEMP%\rarsfx0\i386\mscomm32.ocx
- %TEMP%\rarsfx0\i386\mscomctl32.ocx
- %TEMP%\rarsfx0\i386\mscomctl.ocx
- %TEMP%\rarsfx0\i386\mscomct2.ocx
- %TEMP%\rarsfx0\i386\mfc71u.dll
- %TEMP%\rarsfx0\i386\mfc71kor.dll
- %TEMP%\rarsfx0\i386\mfc71ita.dll
- %TEMP%\rarsfx0\i386\mfc71jpn.dll
- %TEMP%\rarsfx0\i386\msvcp70.dll
- %TEMP%\rarsfx0\i386\msvcp71.dll
- %TEMP%\rarsfx0\i386\vbrun300.dll
- %TEMP%\rarsfx0\i386\vbrun200.dll
- %TEMP%\rarsfx0\i386\vbrun100.dll
- %TEMP%\rarsfx0\i386\vb40032.dll
- %TEMP%\rarsfx0\i386\vb40016.dll
- %TEMP%\rarsfx0\i386\tabctl32.ocx
- %TEMP%\rarsfx0\i386\sysinfo.ocx
- %TEMP%\rarsfx0\i386\richtx32.ocx
- %TEMP%\rarsfx0\i386\mfc70fra.dll
- %TEMP%\rarsfx0\i386\plugin.dll
- %TEMP%\rarsfx0\i386\picclp32.ocx
- %TEMP%\rarsfx0\i386\openal32.dll
- %TEMP%\rarsfx0\i386\mswinsck.ocx
- %TEMP%\rarsfx0\i386\msvcrt10.dll
- %TEMP%\rarsfx0\i386\msvcr71.dll
- %TEMP%\rarsfx0\i386\msvcr70.dll
- %TEMP%\rarsfx0\i386\mfc71fra.dll
- %TEMP%\rarsfx0\i386\mfc71esp.dll
- %TEMP%\rarsfx0\i386\mfc71enu.dll
- %TEMP%\rarsfx0\i386\libeay32.dll
- %TEMP%\rarsfx0\i386\dblist32.ocx
- %TEMP%\rarsfx0\i386\cygwinb19.dll
- %TEMP%\rarsfx0\i386\cygwin1.dll
- %TEMP%\rarsfx0\i386\comdlg32.ocx
- %TEMP%\rarsfx0\i386\comctl32.ocx
- %TEMP%\rarsfx0\i386\comct332.ocx
- %TEMP%\rarsfx0\i386\comct232.ocx
- %TEMP%\rarsfx0\i386\autoitx3.dll
- %TEMP%\rarsfx0\i386\atl71.dll
- %TEMP%\rarsfx0\i386\atl70.dll
- %TEMP%\rarsfx0\setups.ini
- %TEMP%\rarsfx0\setups.exe
- %TEMP%\rarsfx0\runtimes.inf
- %TEMP%\rarsfx0\i386\libintl3.dll
- %TEMP%\rarsfx0\i386\libmmd.dll
- %TEMP%\rarsfx0\i386\libiconv2.dll
- %TEMP%\rarsfx0\i386\libpng13.dll
- %TEMP%\rarsfx0\i386\mfc71deu.dll
- %TEMP%\rarsfx0\i386\libssl32.dll
- %TEMP%\rarsfx0\i386\mfc71cht.dll
- %TEMP%\rarsfx0\i386\mfc71chs.dll
- %TEMP%\rarsfx0\i386\mfc71.dll
- %TEMP%\rarsfx0\i386\mfc70u.dll
- %TEMP%\rarsfx0\i386\mfc70kor.dll
- %TEMP%\rarsfx0\i386\mfc70jpn.dll
- %TEMP%\rarsfx0\i386\ssleay32.dll
- %TEMP%\rarsfx0\i386\wrap_oal.dll
- %TEMP%\rarsfx0\i386\mfc70esp.dll
- %TEMP%\rarsfx0\i386\mfc70enu.dll
- %TEMP%\rarsfx0\i386\mfc70deu.dll
- %TEMP%\rarsfx0\i386\mfc70cht.dll
- %TEMP%\rarsfx0\i386\mfc70chs.dll
- %TEMP%\rarsfx0\i386\mfc70.dll
- %TEMP%\rarsfx0\i386\mci32.ocx
- %TEMP%\rarsfx0\i386\mfc70ita.dll
- %TEMP%\rarsfx0\i386\zlib1.dll
- from %WINDIR%\system\set4172.tmp to %WINDIR%\system\msvcrt10.dll
- from %WINDIR%\syswow64\set49e0.tmp to %WINDIR%\syswow64\mshflxgd.ocx
- from %WINDIR%\syswow64\set49c0.tmp to %WINDIR%\syswow64\msflxgrd.ocx
- from %WINDIR%\syswow64\set49a0.tmp to %WINDIR%\syswow64\msdatlst.ocx
- from %WINDIR%\syswow64\set4980.tmp to %WINDIR%\syswow64\msdatgrd.ocx
- from %WINDIR%\syswow64\set495f.tmp to %WINDIR%\syswow64\mscomm32.ocx
- from %WINDIR%\syswow64\set493f.tmp to %WINDIR%\syswow64\mscomctl32.ocx
- from %WINDIR%\syswow64\set47af.tmp to %WINDIR%\syswow64\mfc71deu.dll
- from %WINDIR%\syswow64\set490f.tmp to %WINDIR%\syswow64\mscomctl.ocx
- from %WINDIR%\syswow64\set4881.tmp to %WINDIR%\syswow64\mfc71u.dll
- from %WINDIR%\syswow64\set4861.tmp to %WINDIR%\syswow64\mfc71kor.dll
- from %WINDIR%\syswow64\set4850.tmp to %WINDIR%\syswow64\mfc71jpn.dll
- from %WINDIR%\syswow64\set4830.tmp to %WINDIR%\syswow64\mfc71ita.dll
- from %WINDIR%\syswow64\set4810.tmp to %WINDIR%\syswow64\mfc71fra.dll
- from %WINDIR%\syswow64\set47e0.tmp to %WINDIR%\syswow64\mfc71esp.dll
- from %WINDIR%\syswow64\set48a1.tmp to %WINDIR%\syswow64\mscomct2.ocx
- from %WINDIR%\syswow64\set47c0.tmp to %WINDIR%\syswow64\mfc71enu.dll
- from %WINDIR%\syswow64\set49f1.tmp to %WINDIR%\syswow64\msinet.ocx
- from %WINDIR%\syswow64\set4b51.tmp to %WINDIR%\syswow64\mswinsck.ocx
- from %WINDIR%\syswow64\set4c42.tmp to %WINDIR%\syswow64\vb40032.dll
- from %WINDIR%\syswow64\set4c31.tmp to %WINDIR%\syswow64\tabctl32.ocx
- from %WINDIR%\syswow64\set4c02.tmp to %WINDIR%\syswow64\sysinfo.ocx
- from %WINDIR%\syswow64\set4be1.tmp to %WINDIR%\syswow64\ssleay32.dll
- from %WINDIR%\syswow64\set4bb2.tmp to %WINDIR%\syswow64\richtx32.ocx
- from %WINDIR%\syswow64\set4b91.tmp to %WINDIR%\syswow64\picclp32.ocx
- from %WINDIR%\syswow64\set4a31.tmp to %WINDIR%\syswow64\msstdfmt.dll
- from %WINDIR%\syswow64\set4a11.tmp to %WINDIR%\syswow64\msmask32.ocx
- from %WINDIR%\syswow64\set4b31.tmp to %WINDIR%\syswow64\msvcr71.dll
- from %WINDIR%\syswow64\set4b01.tmp to %WINDIR%\syswow64\msvcr70.dll
- from %WINDIR%\syswow64\set4ac2.tmp to %WINDIR%\syswow64\msvcp71.dll
- from %WINDIR%\syswow64\set4aa1.tmp to %WINDIR%\syswow64\msvcp70.dll
- from %WINDIR%\syswow64\set4a81.tmp to %WINDIR%\syswow64\msvci70.dll
- from %WINDIR%\syswow64\set4a61.tmp to %WINDIR%\syswow64\msstkprp.dll
- from %WINDIR%\syswow64\set4b71.tmp to %WINDIR%\syswow64\openal32.dll
- from %WINDIR%\syswow64\set479f.tmp to %WINDIR%\syswow64\mfc71cht.dll
- from %WINDIR%\syswow64\set477e.tmp to %WINDIR%\syswow64\mfc71chs.dll
- from %WINDIR%\syswow64\set474f.tmp to %WINDIR%\syswow64\mfc71.dll
- from %WINDIR%\syswow64\set4305.tmp to %WINDIR%\syswow64\cygwin1.dll
- from %WINDIR%\syswow64\set42e5.tmp to %WINDIR%\syswow64\comdlg32.ocx
- from %WINDIR%\syswow64\set42c5.tmp to %WINDIR%\syswow64\comctl32.ocx
- from %WINDIR%\syswow64\set4295.tmp to %WINDIR%\syswow64\comct332.ocx
- from %WINDIR%\syswow64\set4284.tmp to %WINDIR%\syswow64\comct232.ocx
- from %WINDIR%\syswow64\set4394.tmp to %WINDIR%\syswow64\dblist32.ocx
- from %WINDIR%\syswow64\set4274.tmp to %WINDIR%\syswow64\autoitx3.dll
- from %WINDIR%\syswow64\set4243.tmp to %WINDIR%\syswow64\atl70.dll
- from %WINDIR%\system\set4232.tmp to %WINDIR%\system\vbrun300.dll
- from %WINDIR%\system\set4212.tmp to %WINDIR%\system\vbrun200.dll
- from %WINDIR%\system\set41f2.tmp to %WINDIR%\system\vbrun100.dll
- from %WINDIR%\system\set41c2.tmp to %WINDIR%\system\vb40016.dll
- from %WINDIR%\system\set41a2.tmp to %WINDIR%\system\plugin.dll
- from %WINDIR%\syswow64\set4263.tmp to %WINDIR%\syswow64\atl71.dll
- from %WINDIR%\syswow64\set43b4.tmp to %WINDIR%\syswow64\libeay32.dll
- from %WINDIR%\syswow64\set4383.tmp to %WINDIR%\syswow64\cygwinb19.dll
- from %WINDIR%\syswow64\set43f3.tmp to %WINDIR%\syswow64\libiconv2.dll
- from %WINDIR%\syswow64\set472e.tmp to %WINDIR%\syswow64\mfc70u.dll
- from %WINDIR%\syswow64\set460f.tmp to %WINDIR%\syswow64\mfc70deu.dll
- from %WINDIR%\syswow64\set46ff.tmp to %WINDIR%\syswow64\mfc70kor.dll
- from %WINDIR%\syswow64\set46a0.tmp to %WINDIR%\syswow64\mfc70jpn.dll
- from %WINDIR%\syswow64\set4680.tmp to %WINDIR%\syswow64\mfc70ita.dll
- from %WINDIR%\syswow64\set4660.tmp to %WINDIR%\syswow64\mfc70fra.dll
- from %WINDIR%\syswow64\set464f.tmp to %WINDIR%\syswow64\mfc70esp.dll
- from %WINDIR%\syswow64\set463e.tmp to %WINDIR%\syswow64\mfc70enu.dll
- from %WINDIR%\syswow64\set45c0.tmp to %WINDIR%\syswow64\mfc70cht.dll
- from %WINDIR%\syswow64\set4452.tmp to %WINDIR%\syswow64\libintl3.dll
- from %WINDIR%\syswow64\set459f.tmp to %WINDIR%\syswow64\mfc70chs.dll
- from %WINDIR%\syswow64\set4550.tmp to %WINDIR%\syswow64\mfc70.dll
- from %WINDIR%\syswow64\set4530.tmp to %WINDIR%\syswow64\mci32.ocx
- from %WINDIR%\syswow64\set4520.tmp to %WINDIR%\syswow64\libssl32.dll
- from %WINDIR%\syswow64\set450f.tmp to %WINDIR%\syswow64\libpng13.dll
- from %WINDIR%\syswow64\set44a1.tmp to %WINDIR%\syswow64\libmmd.dll
- from %WINDIR%\syswow64\set4c72.tmp to %WINDIR%\syswow64\wrap_oal.dll
- from %WINDIR%\syswow64\set4c92.tmp to %WINDIR%\syswow64\zlib1.dll
- %LOCALAPPDATA%\microsoft\windows\explorer\explorerstartuplog_runonce.etl
- ClassName: 'EDIT' WindowName: ''
- '%TEMP%\rarsfx0\setups.exe'
- '%WINDIR%\syswow64\reg.exe' import %TEMP%\SetupS.reg' (with hidden window)
- '%WINDIR%\syswow64\rundll32.exe' syssetup,SetupInfObjectInstallAction DefaultInstall 128 %TEMP%\RarSFX0\Runtimes.inf
- '%WINDIR%\syswow64\runonce.exe' -r
- '%WINDIR%\syswow64\grpconv.exe' -o
- '%WINDIR%\syswow64\reg.exe' import %TEMP%\SetupS.reg