Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'wextract_cleanup0' = 'rundll32.exe <SYSTEM32>\advpack.dll,DelNodeRunDLL32 "%TEMP%\IXP000.TMP\"'
- [<HKLM>\SOFTWARE\Classes\MSProgramGroup\Shell\Open\Command] '' = '<SYSTEM32>\grpconv.exe %1'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'GrpConv' = 'grpconv -o'
- '<SYSTEM32>\grpconv.exe' -o
- '<SYSTEM32>\rundll32.exe' shell32.dll,Control_RunDLL main.cpl @0
- '<SYSTEM32>\rundll32.exe' setupapi.dll,InstallHinfSection DefaultInstall 128 %TEMP%\IXP000.TMP\Setup.inf
- '<SYSTEM32>\runonce.exe' -r
- %WINDIR%\Cursors\Chrome Glass\SET8.tmp
- %WINDIR%\Cursors\Chrome Glass\SET7.tmp
- %WINDIR%\Cursors\Chrome Glass\SETA.tmp
- %WINDIR%\Cursors\Chrome Glass\SET9.tmp
- %WINDIR%\Cursors\Chrome Glass\SET4.tmp
- %WINDIR%\Cursors\Chrome Glass\SET3.tmp
- %WINDIR%\Cursors\Chrome Glass\SET6.tmp
- %WINDIR%\Cursors\Chrome Glass\SET5.tmp
- %WINDIR%\Cursors\Chrome Glass\SET10.tmp
- %WINDIR%\Cursors\Chrome Glass\SETF.tmp
- %WINDIR%\Cursors\Chrome Glass\SET12.tmp
- %WINDIR%\Cursors\Chrome Glass\SET11.tmp
- %WINDIR%\Cursors\Chrome Glass\SETC.tmp
- %WINDIR%\Cursors\Chrome Glass\SETB.tmp
- %WINDIR%\Cursors\Chrome Glass\SETE.tmp
- %WINDIR%\Cursors\Chrome Glass\SETD.tmp
- %TEMP%\IXP000.TMP\Wait.ani
- %TEMP%\IXP000.TMP\Handwriting.ani
- %TEMP%\IXP000.TMP\Hand.ani
- %TEMP%\IXP000.TMP\IBeam.cur
- %TEMP%\IXP000.TMP\Help.cur
- %TEMP%\IXP000.TMP\Arrow.cur
- %TEMP%\IXP000.TMP\AppStarting.ani
- %TEMP%\IXP000.TMP\Cross.cur
- %TEMP%\IXP000.TMP\Arrow_Down.cur
- %TEMP%\IXP000.TMP\SizeNWSE.cur
- %TEMP%\IXP000.TMP\SizeNS.cur
- %TEMP%\IXP000.TMP\UpArrow.cur
- %TEMP%\IXP000.TMP\SizeWE.cur
- %TEMP%\IXP000.TMP\Setup.inf
- %TEMP%\IXP000.TMP\NO.ani
- %TEMP%\IXP000.TMP\SizeNESW.cur
- %TEMP%\IXP000.TMP\SizeAll.cur
- from %WINDIR%\Cursors\Chrome Glass\SETD.tmp to %WINDIR%\Cursors\Chrome Glass\SizeWE.cur
- from %WINDIR%\Cursors\Chrome Glass\SETE.tmp to %WINDIR%\Cursors\Chrome Glass\SizeNWSE.cur
- from %WINDIR%\Cursors\Chrome Glass\SETB.tmp to %WINDIR%\Cursors\Chrome Glass\NO.ani
- from %WINDIR%\Cursors\Chrome Glass\SETC.tmp to %WINDIR%\Cursors\Chrome Glass\SizeNS.cur
- from %WINDIR%\Cursors\Chrome Glass\SET11.tmp to %WINDIR%\Cursors\Chrome Glass\UpArrow.cur
- from %WINDIR%\Cursors\Chrome Glass\SET12.tmp to %WINDIR%\Cursors\Chrome Glass\Hand.ani
- from %WINDIR%\Cursors\Chrome Glass\SETF.tmp to %WINDIR%\Cursors\Chrome Glass\SizeNESW.cur
- from %WINDIR%\Cursors\Chrome Glass\SET10.tmp to %WINDIR%\Cursors\Chrome Glass\SizeAll.cur
- from %WINDIR%\Cursors\Chrome Glass\SET5.tmp to %WINDIR%\Cursors\Chrome Glass\Help.cur
- from %WINDIR%\Cursors\Chrome Glass\SET6.tmp to %WINDIR%\Cursors\Chrome Glass\AppStarting.ani
- from %WINDIR%\Cursors\Chrome Glass\SET3.tmp to %WINDIR%\Cursors\Chrome Glass\Arrow.cur
- from %WINDIR%\Cursors\Chrome Glass\SET4.tmp to %WINDIR%\Cursors\Chrome Glass\Arrow_Down.cur
- from %WINDIR%\Cursors\Chrome Glass\SET9.tmp to %WINDIR%\Cursors\Chrome Glass\IBeam.cur
- from %WINDIR%\Cursors\Chrome Glass\SETA.tmp to %WINDIR%\Cursors\Chrome Glass\Handwriting.ani
- from %WINDIR%\Cursors\Chrome Glass\SET7.tmp to %WINDIR%\Cursors\Chrome Glass\Wait.ani
- from %WINDIR%\Cursors\Chrome Glass\SET8.tmp to %WINDIR%\Cursors\Chrome Glass\Cross.cur
- ClassName: 'Shell_TrayWnd' WindowName: ''