Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'EXT_InstallerReboot_4CE04779B7FD4755B9A89BB4AFA67474' = '"%TEMP%\SetupTemp0\Starter.exe" /reboot'
- %TEMP%\setuptemp0\config.ini_
- <SYSTEM32>\freeimage.dll
- <SYSTEM32>\sevxpctl.ocx
- <SYSTEM32>\sevtab.ocx
- <SYSTEM32>\sevgraph.ocx
- <SYSTEM32>\sevein20.ocx
- <SYSTEM32>\sevdatagrid2.ocx
- <SYSTEM32>\sevcmd3.ocx
- <SYSTEM32>\sevclb20.ocx
- <SYSTEM32>\gdpicturepro5.ocx
- %TEMP%\13f0ff.msi
- %TEMP%\setuptemp0\file1\kb1022806.msi_
- %TEMP%\logfile_archilinoupdatekb1022806.txt
- %TEMP%\setuptemp0\title3_1031.rtf_
- %TEMP%\setuptemp0\title2_1031.rtf_
- %TEMP%\setuptemp0\title1_1031.rtf_
- %TEMP%\setuptemp0\gfx1.bmp_
- %TEMP%\setuptemp0\config.ini
- %TEMP%\setuptemp0\starter.exe_
- %TEMP%\setuptemp0\bstools.dll_
- %TEMP%\setuptemp0\bssetup.exe.manifest_
- %TEMP%\setuptemp0\bssetup.exe_
- %TEMP%\setuptemp0\bsboot.exe.manifest_
- %TEMP%\setuptemp0\bsboot.exe_
- %ProgramFiles%\archilino update kb1022806\ext_btstr.cfg
- %TEMP%\bsidelst.bat
- %TEMP%\13f0ff.msi
- %TEMP%\setuptemp0\file1\kb1022806.msi
- %TEMP%\setuptemp0\bstools.dll
- %TEMP%\setuptemp0\config.ini
- %TEMP%\setuptemp0\gfx1.bmp
- %TEMP%\setuptemp0\<File name>.exe
- %TEMP%\setuptemp0\<File name>.exe.manifest
- %TEMP%\setuptemp0\<File name>_elevated.exe
- %TEMP%\setuptemp0\<File name>_elevated.exe.manifest
- %TEMP%\setuptemp0\starter.exe
- %TEMP%\setuptemp0\title1_1031.rtf
- %TEMP%\setuptemp0\title2_1031.rtf
- %TEMP%\setuptemp0\title3_1031.rtf
- %ProgramFiles%\archilino update kb1022806\ext_btstr.cfg
- from %TEMP%\setuptemp0\config.ini_ to %TEMP%\setuptemp0\config.ini
- from %TEMP%\setuptemp0\bsboot.exe_ to %TEMP%\setuptemp0\bsboot.exe
- from %TEMP%\setuptemp0\bsboot.exe.manifest_ to %TEMP%\setuptemp0\bsboot.exe.manifest
- from %TEMP%\setuptemp0\bssetup.exe_ to %TEMP%\setuptemp0\bssetup.exe
- from %TEMP%\setuptemp0\bssetup.exe.manifest_ to %TEMP%\setuptemp0\bssetup.exe.manifest
- from %TEMP%\setuptemp0\bstools.dll_ to %TEMP%\setuptemp0\bstools.dll
- from %TEMP%\setuptemp0\starter.exe_ to %TEMP%\setuptemp0\starter.exe
- from %TEMP%\setuptemp0\bssetup.exe to %TEMP%\setuptemp0\<File name>.exe
- from %TEMP%\setuptemp0\bssetup.exe.manifest to %TEMP%\setuptemp0\<File name>.exe.manifest
- from %TEMP%\setuptemp0\bsboot.exe to %TEMP%\setuptemp0\<File name>_elevated.exe
- from %TEMP%\setuptemp0\bsboot.exe.manifest to %TEMP%\setuptemp0\<File name>_elevated.exe.manifest
- from %TEMP%\setuptemp0\gfx1.bmp_ to %TEMP%\setuptemp0\gfx1.bmp
- from %TEMP%\setuptemp0\title1_1031.rtf_ to %TEMP%\setuptemp0\title1_1031.rtf
- from %TEMP%\setuptemp0\title2_1031.rtf_ to %TEMP%\setuptemp0\title2_1031.rtf
- from %TEMP%\setuptemp0\title3_1031.rtf_ to %TEMP%\setuptemp0\title3_1031.rtf
- from %TEMP%\setuptemp0\file1\kb1022806.msi_ to %TEMP%\setuptemp0\file1\kb1022806.msi
- %TEMP%\setuptemp0\config.ini
- '%TEMP%\setuptemp0\<File name>.exe'
- '%TEMP%\setuptemp0\<File name>_elevated.exe'
- '<SYSTEM32>\cmd.exe' /c %TEMP%\BSIDelST.bat' (with hidden window)
- '<SYSTEM32>\msiexec.exe' /V
- '<SYSTEM32>\msiexec.exe' -Embedding DCA1E98E717D59465EDE38A55149C7B2
- '<SYSTEM32>\cmd.exe' /c %TEMP%\BSIDelST.bat