Technical Information
- <SYSTEM32>\tasks\microsoft\windows\xndpupdate\widowsxndp
- '<Full path to file>' (downloaded from the Internet)
- %TEMP%\xnewlooksetup_1251ro5gpfcgp9mx0s_2911.exe
- %TEMP%\fastshot_x_tn_100006.exe
- %TEMP%\is-mvu9r.tmp\xnewlooksetup_1251ro5gpfcgp9mx0s_2911.tmp
- %TEMP%\is-ae6d8.tmp\_isetup\_setup64.tmp
- %TEMP%\is-ae6d8.tmp\mydll.dll
- %ProgramFiles(x86)%\xnewlook\is-3044s.tmp
- %ProgramFiles(x86)%\xnewlook\is-qj95g.tmp
- %ProgramFiles(x86)%\xnewlook\is-lj060.tmp
- %ProgramFiles(x86)%\xnewlook\is-4mgqk.tmp
- %ProgramFiles(x86)%\xnewlook\is-cqvt3.tmp
- %ProgramFiles(x86)%\xnewlook\is-fiuhm.tmp
- %ProgramFiles(x86)%\xnewlook\is-v301t.tmp
- %ProgramFiles(x86)%\xnewlook\is-qtp19.tmp
- %ProgramFiles(x86)%\xnewlook\is-hel5d.tmp
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\小新看图\启动 小新看图.lnk
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\小新看图\卸载 小新看图.lnk
- %TEMP%\quarkpc_v4.0.5.355_pc_pf30002_(zh-cn)_release_(build2205244-250523230213-x64).exe
- %TEMP%\nsi7c51.tmp
- %TEMP%\nsi7c52.tmp\system.dll
- %TEMP%\nsi7c52.tmp\res\skin\ask_icon.png
- %TEMP%\nsi7c52.tmp\res\skin\banner.png
- %TEMP%\nsi7c52.tmp\res\skin\banner_success.png
- %ProgramFiles(x86)%\xnewlook\unins000.msg
- %ProgramFiles(x86)%\xnewlook\unins000.dat
- %TEMP%\nsi7c52.tmp\res\skin\bg.png
- %TEMP%\nsi7c52.tmp\res\skin\btn_blue_90_30.png
- %TEMP%\nsi7c52.tmp\res\skin\btn_close_1.png
- %TEMP%\nsi7c52.tmp\res\skin\btn_expand.png
- %TEMP%\nsi7c52.tmp\res\skin\btn_install.png
- %TEMP%\nsi7c52.tmp\res\skin\btn_push.png
- %TEMP%\nsi7c52.tmp\res\skin\checkbox.png
- %TEMP%\nsi7c52.tmp\res\skin\checkbox1.png
- %TEMP%\nsi7c52.tmp\res\skin\checkout.png
- %TEMP%\nsi7c52.tmp\res\skin\dot_down.png
- %TEMP%\nsi7c52.tmp\res\skin\dot_up.png
- %TEMP%\nsi7c52.tmp\res\skin\info_icon.png
- %TEMP%\nsi7c52.tmp\res\skin\main.png
- %TEMP%\nsi7c52.tmp\res\skin\main_bg.png
- %TEMP%\nsi7c52.tmp\res\skin\sorry.png
- %TEMP%\nsi7c52.tmp\res\skin\top_caption.png
- %TEMP%\nsi7c52.tmp\res\skin\triangle.png
- %TEMP%\nsi7c52.tmp\res\skin\upgrade.png
- %TEMP%\nsi7c52.tmp\res\skin\upgrade_ok.png
- %TEMP%\nsi7c52.tmp\res\skin\view_bg.png
- %TEMP%\nsi7c52.tmp\res\skin\win_close.png
- %TEMP%\nsi7c52.tmp\res\skin\win_close_hover.png
- %TEMP%\nsi7c52.tmp\res\skin\win_min.png
- %TEMP%\nsi7c52.tmp\insthelper.dll
- %ALLUSERSPROFILE%\9cc84e23-75a4-41f9-82b5-67f4fd9e78a7\common\global.db
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\fastshot.ico
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\bg.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\btn_1_1.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\btn_1_1_disable.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\btn_backward.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\btn_backward_disable.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\btn_blue_90_30.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\btn_download.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\btn_download_disable.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\btn_fix.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\btn_fix_disable.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\btn_forward.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\btn_forward_disable.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\btn_leftright.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\btn_leftright_disable.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\btn_orient.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\btn_round.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\btn_round_disable.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\btn_updown.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\btn_updown_disable.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\btn_zoomin.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\btn_zoomin_disable.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\btn_zoomout.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\btn_zoomout_disable.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\checkbox.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\ellips_capture.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\fastshotmaster.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\fastshotmaster_48.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\frame.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\frame_hover.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\ico_screenshot.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\icon_popup_up.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\image_none.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\keyboard.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\logo.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\longdown_capture.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\longup_capture.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\main.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\master_left.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\ocr_capture.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\play.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\radiobox.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\record_continue.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\record_pause.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\record_stop.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\rectangle_capture.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\setting.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\setting_sel.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\sound_close.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\sound_disable.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\sound_open.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\success.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\tab_capture.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\tab_hover.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\tab_longcapture.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\tab_record.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\tab_setting.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\tips_bkg.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\toolbar.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\toolbtn_arrow.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\toolbtn_arrow_p.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\toolbtn_brush.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\toolbtn_brush_p.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\toolbtn_cancel.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\toolbtn_done.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\toolbtn_elli.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\toolbtn_elli_p.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\toolbtn_long_down.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\toolbtn_long_up.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\toolbtn_masc.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\toolbtn_masc_p.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\toolbtn_ocr.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\toolbtn_pen.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\toolbtn_pen_p.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\toolbtn_record.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\toolbtn_rectangle.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\toolbtn_rectangle_p.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\toolbtn_redo.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\toolbtn_redo_disable.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\toolbtn_reset.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\toolbtn_save.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\toolbtn_text.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\toolbtn_text_p.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\toolbtn_undo.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\toolbtn_undo_disable.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\view_bg.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\win_close.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\win_close_hover.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\win_max.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\win_min.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\skins\win_restore.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\ocr\fastshotocr.exe
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\ocr\archive.dll
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\ocr\bz2.dll
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\ocr\gif.dll
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\ocr\jpeg62.dll
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\ocr\leptonica-1.84.1.dll
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\ocr\libcrypto-3.dll
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\ocr\libcurl.dll
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\ocr\liblzma.dll
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\ocr\libpng16.dll
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\ocr\libsharpyuv.dll
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\ocr\libwebp.dll
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\ocr\libwebpmux.dll
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\ocr\lz4.dll
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\ocr\opencv_core4.dll
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\ocr\opencv_imgcodecs4.dll
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\ocr\opencv_imgproc4.dll
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\ocr\openjp2.dll
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\ocr\tesseract.exe
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\ocr\tesseract53.dll
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\ocr\tiff.dll
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\ocr\turbojpeg.dll
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\ocr\zlib1.dll
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\ocr\zstd.dll
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\ocr\skins\btn_scanning.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\ocr\skins\btn_scanning_ed.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\ocr\skins\ocr_slogen.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\ocr\skins\open_file.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\ocr\skins\save_file.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\ocr\skins\tips_bkg.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\ocr\skins\view_bg.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\ocr\skins\win_close.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\ocr\skins\win_close_hover.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\ocr\skins\win_logo.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\ocr\skins\win_max.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\ocr\skins\win_max_hover.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\ocr\skins\win_min.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\ocr\skins\win_restore.png
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\bugreport.exe
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\fastassist.dll
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\fasttips.exe
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\fastshot.exe
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\fastshotmaster.exe
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\fastshottray.exe
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\fastshotview.exe
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\ipcprovider.dll
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\upgrader.exe
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\vc_redist_2022.x86.exe
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\avcodec-60.dll
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\avdevice-60.dll
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\avfilter-9.dll
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\avformat-60.dll
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\avutil-58.dll
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\jpeg62.dll
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\libcrypto-3.dll
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\libcurl.dll
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\liblzma.dll
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\libpng16.dll
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\libsharpyuv.dll
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\libwebp.dll
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\libwebpdecoder.dll
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\lz4.dll
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\opencv_calib3d4.dll
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\opencv_core4.dll
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\opencv_features2d4.dll
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\opencv_flann4.dll
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\opencv_imgcodecs4.dll
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\opencv_imgproc4.dll
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\openjp2.dll
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\swresample-4.dll
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\swscale-7.dll
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\tiff.dll
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\turbojpeg.dll
- %LOCALAPPDATA%\programs\fastshot\1.1.0.46\zlib1.dll
- %TEMP%\is-ae6d8.tmp\mydll.dll
- %TEMP%\is-ae6d8.tmp\_isetup\_setup64.tmp
- %TEMP%\is-mvu9r.tmp\xnewlooksetup_1251ro5gpfcgp9mx0s_2911.tmp
- from %ProgramFiles(x86)%\xnewlook\is-3044s.tmp to %ProgramFiles(x86)%\xnewlook\unins000.exe
- from %ProgramFiles(x86)%\xnewlook\is-qj95g.tmp to %ProgramFiles(x86)%\xnewlook\xnewlook.exe
- from %ProgramFiles(x86)%\xnewlook\is-lj060.tmp to %ProgramFiles(x86)%\xnewlook\xnewlookdecoder.dll
- from %ProgramFiles(x86)%\xnewlook\is-4mgqk.tmp to %ProgramFiles(x86)%\xnewlook\xnewlookrender.dll
- from %ProgramFiles(x86)%\xnewlook\is-cqvt3.tmp to %ProgramFiles(x86)%\xnewlook\xnewlooksch.dll
- from %ProgramFiles(x86)%\xnewlook\is-fiuhm.tmp to %ProgramFiles(x86)%\xnewlook\xnewlooksvc.dll
- from %ProgramFiles(x86)%\xnewlook\is-v301t.tmp to %ProgramFiles(x86)%\xnewlook\xnewlookui.dll
- from %ProgramFiles(x86)%\xnewlook\is-qtp19.tmp to %ProgramFiles(x86)%\xnewlook\xnewlookupdate.exe
- from %ProgramFiles(x86)%\xnewlook\is-hel5d.tmp to %ProgramFiles(x86)%\xnewlook\xnewlookutil.dll
- 'do####ad.xp666.com':80
- 'do#####d.xinbowei.cn':80
- 'cd#.#in-02.com':80
- 'um###.quark.cn':80
- 'ms#.#inbowei.cn':6934
- 'ap#.##stscreen.cn':8008
- http://do####ad.xp666.com/xzqswf/cof/inst_date2.cfg
- http://do#####d.xinbowei.cn/xnew/XNewLookSetup_1251RO5gpFcGP9mx0s_2911.exe
- http://cd#.#in-02.com/fastshot/packages/finaly/fastshot_x_tn_100006.exe
- http://um###.quark.cn/download/37212/quarkpc/pcquark@other_baoyingpckk_cpa2/QuarkPC_V4.0.5.355_pc_pf30002_(zh-cn)_release_(Build2205244-250523230213-x64).exe
- 'ms#.#inbowei.cn':6934
- DNS ASK do####ad.xp666.com
- DNS ASK do#####d.xinbowei.cn
- DNS ASK cd#.#in-02.com
- DNS ASK um###.quark.cn
- DNS ASK ms#.#inbowei.cn
- DNS ASK hb##.#ulishax.cn
- DNS ASK re#####u.cleanmoon.cn
- DNS ASK ap#.##stscreen.cn
- ClassName: 'LogView_qqpcmgr' WindowName: ''
- '%TEMP%\xnewlooksetup_1251ro5gpfcgp9mx0s_2911.exe'
- '%TEMP%\is-mvu9r.tmp\xnewlooksetup_1251ro5gpfcgp9mx0s_2911.tmp' /SL5="$60244,3248238,843264,%TEMP%\XNewLookSetup_1251RO5gpFcGP9mx0s_2911.exe"
- '%ProgramFiles(x86)%\xnewlook\xnewlook.exe' /mapt /SL5="$60244,3248238,843264,%TEMP%\XNewLookSetup_1251RO5gpFcGP9mx0s_2911.exe"
- '%TEMP%\fastshot_x_tn_100006.exe' /S
- '%LOCALAPPDATA%\programs\fastshot\1.1.0.46\vc_redist_2022.x86.exe' /quiet /norestart
- '%WINDIR%\syswow64\rundll32.exe' "%ProgramFiles(x86)%\XNewLook\XNewLookSch.dll",DllRegisterServer
- '%ProgramFiles(x86)%\xnewlook\xnewlook.exe' /mapt /SL5="$60244,3248238,843264,%TEMP%\XNewLookSetup_1251RO5gpFcGP9mx0s_2911.exe"' (with hidden window)
- '%WINDIR%\syswow64\rundll32.exe' "%ProgramFiles(x86)%\XNewLook\XNewLookSch.dll",DllRegisterServer' (with hidden window)
- '%WINDIR%\temp\{a818d67d-fb0e-472c-aafc-a4faa65ef906}\.be\vc_redist.x86.exe' -q -burn.elevated BurnPipe.{901D6F17-FF6D-47A8-8362-CE021A3FABAB} {5AE5DC0D-77D0-40AD-89C8-D07A6587FA21} 2708' (with hidden window)