Technical Information
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'MWREGICBC.exe' = '"%ProgramFiles(x86)%\ICBCEbankTools\MingWah\MWREGICBC.exe"'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'MWREGICBC_NEW.exe' = '"%ProgramFiles(x86)%\ICBCEbankTools\MingWah\MWICBCUKeyToolU.exe" /RunMode AutoRun'
- %WINDIR%\tasks\icbcmwautoruntask.job
- <SYSTEM32>\tasks\icbcmwautoruntask
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2] '2201' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2] '1405' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2] '120B' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2] '1004' = '00000001'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2] '1001' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2] '1208' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2] '1200' = '00000000'
- %TEMP%\midwarev2package_a80b0da5\combinefile.combine
- %ProgramFiles(x86)%\icbcebanktools\mingwah\0000347b00007440.esf
- %ProgramFiles(x86)%\icbcebanktools\mingwah\000034b000001406.esf
- %ProgramFiles(x86)%\icbcebanktools\mingwah\000034e1000009d0.esf
- %ProgramFiles(x86)%\icbcebanktools\mingwah\000036140000747f.esf
- %ProgramFiles(x86)%\icbcebanktools\mingwah\000036de00001fa0.esf
- %WINDIR%\syswow64\0000374700005f2d.esf
- %WINDIR%\syswow64\0000397500006ac6.esf
- %WINDIR%\syswow64\000039a900000a8d.esf
- %WINDIR%\syswow64\00003a74000035ae.esf
- %WINDIR%\syswow64\00003b7200000096.esf
- %WINDIR%\syswow64\00003c7100004b7d.esf
- <SYSTEM32>\00003c7100004b7d.esf
- %TEMP%\midwarev2package_a80b0da5\packagefiles\installconfig_id.ini
- <SYSTEM32>\00003da40000362c.esf
- <SYSTEM32>\00003ed7000020da.esf
- <SYSTEM32>\000040070000618c.esf
- %WINDIR%\downloaded program files\000040070000618c.esf
- %WINDIR%\downloaded program files\0000483100005890.esf
- %WINDIR%\downloaded program files\000071fb00002293.esf
- %WINDIR%\downloaded program files\00007a5600000f61.esf
- %ProgramFiles(x86)%\icbcebanktools\icbcebankplugin\0000008200007096.esf
- %ProgramFiles(x86)%\icbcebanktools\icbcebankplugin\000000b300006660.esf
- %ProgramFiles(x86)%\icbcebanktools\mingwah\uninstall.exe
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\client-end software of icbc internet banking\mw&wdc\ukey managertool(mw&wdc).lnk
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\client-end software of icbc internet banking\mw&wdc\uninstall.lnk
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\client-end software of icbc internet banking\mw&wdc\guide to usb-shield.lnk
- %ProgramFiles(x86)%\icbcebanktools\mingwah\0000341600005eaf.esf
- %ProgramFiles(x86)%\icbcebanktools\mingwah\0000344a00007e76.esf
- %ProgramFiles(x86)%\icbcebanktools\mingwah\res\000033e200003ee9.esf
- %ProgramFiles(x86)%\icbcebanktools\mingwah\res\000033b10000491f.esf
- %ProgramFiles(x86)%\icbcebanktools\mingwah\res\0000337d00002958.esf
- %TEMP%\midwarev2package_a80b0da5\logo.png
- %TEMP%\midwarev2package_a80b0da5\logo.ico
- %TEMP%\midwarev2package_a80b0da5\splash.bmp
- %TEMP%\midwarev2package_a80b0da5\packagefiles\installconfig_common.ini
- %TEMP%\midwarev2package_a80b0da5\uninstall.exe
- %TEMP%\midwarev2package_a80b0da5\packagefiles\installconfig_cn.ini
- %TEMP%\midwarev2package_a80b0da5\packagefiles\installconfig_tc.ini
- %TEMP%\midwarev2package_a80b0da5\packagefiles\installconfig_en.ini
- %TEMP%\midwarev2package_a80b0da5\packagefiles\installconfig_ru.ini
- %TEMP%\midwarev2package_a80b0da5\packagefiles\installconfig_fr.ini
- %TEMP%\midwarev2package_a80b0da5\packagefiles\installconfig_jp.ini
- %TEMP%\midwarev2package_a80b0da5\packagefiles\installconfig_kr.ini
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\client-end software of icbc internet banking\mw&wdc\icbc internet banking.lnk
- <SYSTEM32>\00003ea300000113.esf
- %TEMP%\midwarev2package_a80b0da5\packagefiles\installconfig_ar.ini
- %TEMP%\midwarev2package_a80b0da5\packagefiles\installconfig_th.ini
- %TEMP%\midwarev2package_a80b0da5\packagefiles\installconfig_de.ini
- %TEMP%\midwarev2package_a80b0da5\packagefiles\installconfig_kz.ini
- %TEMP%\midwarev2package_a80b0da5\packagefiles\installconfig_nl.ini
- %TEMP%\midwarev2package_a80b0da5\packagefiles\addin(x64)\osproxy64.exe
- %TEMP%\4d26572043535020666f722049434243205635.bin
- %TEMP%\midwarev2package_a80b0da5\packagefiles\reg\0000327e00005e70.esf
- %TEMP%\midwarev2package_a80b0da5\packagefiles\certtoreg\0000327e00005e70.esf
- %TEMP%\midwarev2package_a80b0da5\packagefiles\certtoreg\000032b200007e37.esf
- %ProgramFiles(x86)%\icbcebanktools\mingwah\res\000032e300007401.esf
- %ProgramFiles(x86)%\icbcebanktools\mingwah\res\00003317000013c7.esf
- %ProgramFiles(x86)%\icbcebanktools\mingwah\res\0000334c0000338e.esf
- %TEMP%\midwarev2package_a80b0da5\installconfig.xml
- %TEMP%\midwarev2package_a80b0da5\packagefiles\installconfig_pl.ini
- C:\users\public\desktop\icbc internet banking.lnk
- %WINDIR%\syswow64\0000374700005f2d.esf
- %TEMP%\midwarev2package_a80b0da5\packagefiles\reg\x86_64.reg
- %TEMP%\midwarev2package_a80b0da5\packagefiles\installconfig_th.ini
- %TEMP%\midwarev2package_a80b0da5\packagefiles\installconfig_tc.ini
- %TEMP%\midwarev2package_a80b0da5\packagefiles\installconfig_ru.ini
- %TEMP%\midwarev2package_a80b0da5\packagefiles\installconfig_pl.ini
- %TEMP%\midwarev2package_a80b0da5\packagefiles\installconfig_nl.ini
- %TEMP%\midwarev2package_a80b0da5\packagefiles\installconfig_kz.ini
- %TEMP%\midwarev2package_a80b0da5\packagefiles\installconfig_kr.ini
- %TEMP%\midwarev2package_a80b0da5\packagefiles\installconfig_jp.ini
- %TEMP%\midwarev2package_a80b0da5\packagefiles\installconfig_id.ini
- %TEMP%\midwarev2package_a80b0da5\packagefiles\installconfig_fr.ini
- %TEMP%\midwarev2package_a80b0da5\packagefiles\installconfig_en.ini
- %TEMP%\midwarev2package_a80b0da5\packagefiles\installconfig_de.ini
- %TEMP%\midwarev2package_a80b0da5\packagefiles\installconfig_common.ini
- %TEMP%\midwarev2package_a80b0da5\packagefiles\installconfig_cn.ini
- %TEMP%\midwarev2package_a80b0da5\packagefiles\installconfig_ar.ini
- %TEMP%\midwarev2package_a80b0da5\packagefiles\certtoreg\icbc_root.cer
- %TEMP%\midwarev2package_a80b0da5\packagefiles\certtoreg\icbc_person_root.cer
- %TEMP%\midwarev2package_a80b0da5\packagefiles\addin(x64)\osproxy64.exe
- %TEMP%\midwarev2package_a80b0da5\logo.png
- %TEMP%\midwarev2package_a80b0da5\logo.ico
- %TEMP%\midwarev2package_a80b0da5\installconfig.xml
- %TEMP%\midwarev2package_a80b0da5\combinefile.combine
- %TEMP%\midwarev2package_a80b0da5\splash.bmp
- %TEMP%\midwarev2package_a80b0da5\uninstall.exe
- from %TEMP%\midwarev2package_a80b0da5\packagefiles\reg\0000327e00005e70.esf to %TEMP%\midwarev2package_a80b0da5\packagefiles\reg\x86_64.reg
- from %ProgramFiles(x86)%\icbcebanktools\mingwah\0000341600005eaf.esf to %ProgramFiles(x86)%\icbcebanktools\mingwah\netbankmidwarev2cfg_ru.ini
- from %ProgramFiles(x86)%\icbcebanktools\mingwah\0000341600005eaf.esf to %ProgramFiles(x86)%\icbcebanktools\mingwah\netbankmidwarev2cfg_fr.ini
- from %ProgramFiles(x86)%\icbcebanktools\mingwah\0000344a00007e76.esf to %ProgramFiles(x86)%\icbcebanktools\mingwah\netbankmidwarev2cfg_jp.ini
- from %ProgramFiles(x86)%\icbcebanktools\mingwah\0000344a00007e76.esf to %ProgramFiles(x86)%\icbcebanktools\mingwah\netbankmidwarev2cfg_kr.ini
- from %ProgramFiles(x86)%\icbcebanktools\mingwah\0000344a00007e76.esf to %ProgramFiles(x86)%\icbcebanktools\mingwah\netbankmidwarev2cfg_ar.ini
- from %ProgramFiles(x86)%\icbcebanktools\mingwah\0000347b00007440.esf to %ProgramFiles(x86)%\icbcebanktools\mingwah\netbankmidwarev2cfg_id.ini
- from %ProgramFiles(x86)%\icbcebanktools\mingwah\0000347b00007440.esf to %ProgramFiles(x86)%\icbcebanktools\mingwah\netbankmidwarev2cfg_pl.ini
- from %ProgramFiles(x86)%\icbcebanktools\mingwah\0000347b00007440.esf to %ProgramFiles(x86)%\icbcebanktools\mingwah\netbankmidwarev2cfg_th.ini
- from %ProgramFiles(x86)%\icbcebanktools\mingwah\000034b000001406.esf to %ProgramFiles(x86)%\icbcebanktools\mingwah\netbankmidwarev2cfg_de.ini
- from %ProgramFiles(x86)%\icbcebanktools\mingwah\000034b000001406.esf to %ProgramFiles(x86)%\icbcebanktools\mingwah\netbankmidwarev2cfg_kz.ini
- from %ProgramFiles(x86)%\icbcebanktools\mingwah\000034b000001406.esf to %ProgramFiles(x86)%\icbcebanktools\mingwah\netbankmidwarev2cfg_nl.ini
- from %ProgramFiles(x86)%\icbcebanktools\mingwah\000034b000001406.esf to %ProgramFiles(x86)%\icbcebanktools\mingwah\mwregicbc.exe
- from %ProgramFiles(x86)%\icbcebanktools\mingwah\000034e1000009d0.esf to %ProgramFiles(x86)%\icbcebanktools\mingwah\mwicbcukeyui.exe
- from %ProgramFiles(x86)%\icbcebanktools\mingwah\000036140000747f.esf to %ProgramFiles(x86)%\icbcebanktools\mingwah\mwicbcukeytoolu.exe
- from %ProgramFiles(x86)%\icbcebanktools\mingwah\000036de00001fa0.esf to %ProgramFiles(x86)%\icbcebanktools\mingwah\icbc user manual_sc.chm
- from %WINDIR%\syswow64\0000397500006ac6.esf to %WINDIR%\syswow64\midwarev2config_icbc.bin
- from %WINDIR%\syswow64\000039a900000a8d.esf to %WINDIR%\syswow64\icbcpkcs11_v1.dll
- from %ProgramFiles(x86)%\icbcebanktools\icbcebankplugin\0000008200007096.esf to %ProgramFiles(x86)%\icbcebanktools\icbcebankplugin\icbc_chrome_mw_nativehost.exe
- from %WINDIR%\downloaded program files\00007a5600000f61.esf to %WINDIR%\downloaded program files\icbcgm_mwusbkey.dll
- from %WINDIR%\downloaded program files\000071fb00002293.esf to %WINDIR%\downloaded program files\icbc_mwusbkey.dll
- from %WINDIR%\downloaded program files\0000483100005890.esf to %WINDIR%\downloaded program files\icbcgm_mwusbkey_64.dll
- from %WINDIR%\downloaded program files\000040070000618c.esf to %WINDIR%\downloaded program files\icbc_mwusbkey_64.dll
- from <SYSTEM32>\000040070000618c.esf to <SYSTEM32>\icbcpkcs11_v1.sig
- from <SYSTEM32>\00003ea300000113.esf to <SYSTEM32>\icbccsps.dll
- from <SYSTEM32>\00003ed7000020da.esf to <SYSTEM32>\esminica.dll
- from <SYSTEM32>\00003da40000362c.esf to <SYSTEM32>\icbcpkcs11_v1.bin
- from <SYSTEM32>\00003c7100004b7d.esf to <SYSTEM32>\icbcpkcs11_v1.dll
- from %WINDIR%\syswow64\00003c7100004b7d.esf to %WINDIR%\syswow64\icbcpkcs11_v1.sig
- from %WINDIR%\syswow64\00003b7200000096.esf to %WINDIR%\syswow64\esminica.dll
- from %WINDIR%\syswow64\00003a74000035ae.esf to %WINDIR%\syswow64\icbccsps.dll
- from %WINDIR%\syswow64\00003a74000035ae.esf to %WINDIR%\syswow64\icbcpkcs11_v1.bin
- from %ProgramFiles(x86)%\icbcebanktools\icbcebankplugin\000000b300006660.esf to %ProgramFiles(x86)%\icbcebanktools\icbcebankplugin\icbc.chrome.mw.plugin-win.json
- from %ProgramFiles(x86)%\icbcebanktools\mingwah\0000341600005eaf.esf to %ProgramFiles(x86)%\icbcebanktools\mingwah\netbankmidwarev2cfg_cn.ini
- from %ProgramFiles(x86)%\icbcebanktools\mingwah\0000341600005eaf.esf to %ProgramFiles(x86)%\icbcebanktools\mingwah\netbankmidwarev2cfg_en.ini
- from %ProgramFiles(x86)%\icbcebanktools\mingwah\0000341600005eaf.esf to %ProgramFiles(x86)%\icbcebanktools\mingwah\netbankmidwarev2cfg_tc.ini
- from %TEMP%\midwarev2package_a80b0da5\packagefiles\reg\0000327e00005e70.esf to %TEMP%\midwarev2package_a80b0da5\packagefiles\reg\x86.reg
- from %TEMP%\midwarev2package_a80b0da5\packagefiles\reg\0000327e00005e70.esf to %TEMP%\midwarev2package_a80b0da5\packagefiles\reg\x64.reg
- from %TEMP%\midwarev2package_a80b0da5\packagefiles\certtoreg\0000327e00005e70.esf to %TEMP%\midwarev2package_a80b0da5\packagefiles\certtoreg\icbc_root.cer
- from %TEMP%\midwarev2package_a80b0da5\packagefiles\certtoreg\000032b200007e37.esf to %TEMP%\midwarev2package_a80b0da5\packagefiles\certtoreg\icbc_person_root.cer
- from %TEMP%\midwarev2package_a80b0da5\packagefiles\certtoreg\000032b200007e37.esf to %TEMP%\midwarev2package_a80b0da5\packagefiles\certtoreg\icbc_person_ca.cer
- from %TEMP%\midwarev2package_a80b0da5\packagefiles\certtoreg\000032b200007e37.esf to %TEMP%\midwarev2package_a80b0da5\packagefiles\certtoreg\icbc_corpor_root.cer
- from %TEMP%\midwarev2package_a80b0da5\packagefiles\certtoreg\000032b200007e37.esf to %TEMP%\midwarev2package_a80b0da5\packagefiles\certtoreg\icbc_corpor_ca.cer
- from %ProgramFiles(x86)%\icbcebanktools\mingwah\res\000032e300007401.esf to %ProgramFiles(x86)%\icbcebanktools\mingwah\res\warning.ico
- from %ProgramFiles(x86)%\icbcebanktools\mingwah\res\000032e300007401.esf to %ProgramFiles(x86)%\icbcebanktools\mingwah\res\usbkey_confirm.png
- from %ProgramFiles(x86)%\icbcebanktools\mingwah\res\00003317000013c7.esf to %ProgramFiles(x86)%\icbcebanktools\mingwah\res\shift_normal.bmp
- from %ProgramFiles(x86)%\icbcebanktools\mingwah\res\00003317000013c7.esf to %ProgramFiles(x86)%\icbcebanktools\mingwah\res\shift_hover.bmp
- from %ProgramFiles(x86)%\icbcebanktools\mingwah\res\00003317000013c7.esf to %ProgramFiles(x86)%\icbcebanktools\mingwah\res\shift_down.bmp
- from %ProgramFiles(x86)%\icbcebanktools\mingwah\res\00003317000013c7.esf to %ProgramFiles(x86)%\icbcebanktools\mingwah\res\managertool.ico
- from %ProgramFiles(x86)%\icbcebanktools\mingwah\res\00003317000013c7.esf to %ProgramFiles(x86)%\icbcebanktools\mingwah\res\mail.ico
- from %ProgramFiles(x86)%\icbcebanktools\mingwah\res\00003317000013c7.esf to %ProgramFiles(x86)%\icbcebanktools\mingwah\res\logomantool.png
- from %ProgramFiles(x86)%\icbcebanktools\mingwah\res\0000334c0000338e.esf to %ProgramFiles(x86)%\icbcebanktools\mingwah\res\logoprocess.png
- from %ProgramFiles(x86)%\icbcebanktools\mingwah\res\0000334c0000338e.esf to %ProgramFiles(x86)%\icbcebanktools\mingwah\res\logo.png
- from %ProgramFiles(x86)%\icbcebanktools\mingwah\res\000033e200003ee9.esf to %ProgramFiles(x86)%\icbcebanktools\mingwah\res\caps_hover.bmp
- from %ProgramFiles(x86)%\icbcebanktools\mingwah\res\000033e200003ee9.esf to %ProgramFiles(x86)%\icbcebanktools\mingwah\res\caps_normal.bmp
- from %ProgramFiles(x86)%\icbcebanktools\mingwah\res\000033e200003ee9.esf to %ProgramFiles(x86)%\icbcebanktools\mingwah\res\cert.ico
- from %ProgramFiles(x86)%\icbcebanktools\mingwah\res\000033e200003ee9.esf to %ProgramFiles(x86)%\icbcebanktools\mingwah\res\close.ico
- from %ProgramFiles(x86)%\icbcebanktools\mingwah\res\000033b10000491f.esf to %ProgramFiles(x86)%\icbcebanktools\mingwah\res\error.ico
- from %ProgramFiles(x86)%\icbcebanktools\mingwah\res\000033b10000491f.esf to %ProgramFiles(x86)%\icbcebanktools\mingwah\res\information.ico
- from %ProgramFiles(x86)%\icbcebanktools\mingwah\res\000033b10000491f.esf to %ProgramFiles(x86)%\icbcebanktools\mingwah\res\keyboard.bmp
- from %ProgramFiles(x86)%\icbcebanktools\mingwah\res\000033b10000491f.esf to %ProgramFiles(x86)%\icbcebanktools\mingwah\res\key.ico
- from %ProgramFiles(x86)%\icbcebanktools\mingwah\res\000033b10000491f.esf to %ProgramFiles(x86)%\icbcebanktools\mingwah\res\keyboard.ico
- from %ProgramFiles(x86)%\icbcebanktools\mingwah\res\0000337d00002958.esf to %ProgramFiles(x86)%\icbcebanktools\mingwah\res\key_down.bmp
- from %ProgramFiles(x86)%\icbcebanktools\mingwah\res\0000337d00002958.esf to %ProgramFiles(x86)%\icbcebanktools\mingwah\res\key_hover.bmp
- from %ProgramFiles(x86)%\icbcebanktools\mingwah\res\0000337d00002958.esf to %ProgramFiles(x86)%\icbcebanktools\mingwah\res\key_normal.bmp
- from %ProgramFiles(x86)%\icbcebanktools\mingwah\res\0000334c0000338e.esf to %ProgramFiles(x86)%\icbcebanktools\mingwah\res\lock.ico
- from %ProgramFiles(x86)%\icbcebanktools\mingwah\res\0000334c0000338e.esf to %ProgramFiles(x86)%\icbcebanktools\mingwah\res\logo.bmp
- from %ProgramFiles(x86)%\icbcebanktools\mingwah\res\000033e200003ee9.esf to %ProgramFiles(x86)%\icbcebanktools\mingwah\res\caps_down.bmp
- from %ProgramFiles(x86)%\icbcebanktools\icbcebankplugin\000000b300006660.esf to %ProgramFiles(x86)%\icbcebanktools\icbcebankplugin\icbc_mw_usbkey_newchrome.crx
- %TEMP%\midwarev2package_a80b0da5\packagefiles\reg\0000327e00005e70.esf
- %TEMP%\midwarev2package_a80b0da5\packagefiles\certtoreg\000032b200007e37.esf
- %ProgramFiles(x86)%\icbcebanktools\mingwah\res\000032e300007401.esf
- %ProgramFiles(x86)%\icbcebanktools\mingwah\res\00003317000013c7.esf
- %ProgramFiles(x86)%\icbcebanktools\mingwah\res\0000334c0000338e.esf
- %ProgramFiles(x86)%\icbcebanktools\mingwah\res\0000337d00002958.esf
- %ProgramFiles(x86)%\icbcebanktools\mingwah\res\000033b10000491f.esf
- %ProgramFiles(x86)%\icbcebanktools\mingwah\res\000033e200003ee9.esf
- %ProgramFiles(x86)%\icbcebanktools\mingwah\0000341600005eaf.esf
- %ProgramFiles(x86)%\icbcebanktools\mingwah\0000344a00007e76.esf
- %ProgramFiles(x86)%\icbcebanktools\mingwah\0000347b00007440.esf
- %ProgramFiles(x86)%\icbcebanktools\mingwah\000034b000001406.esf
- %WINDIR%\syswow64\00003a74000035ae.esf
- %ProgramFiles(x86)%\icbcebanktools\icbcebankplugin\000000b300006660.esf
- '%ProgramFiles(x86)%\icbcebanktools\mingwah\mwicbcukeytoolu.exe' /RunMode AutoRun
- '%ProgramFiles(x86)%\icbcebanktools\mingwah\mwicbcukeyui.exe' /SessionName 49434243_Session1_Admin
- '<SYSTEM32>\regsvr32.exe' /s "%WINDIR%\Downloaded Program Files\icbc_mwusbkey_64.dll"' (with hidden window)
- '<SYSTEM32>\regsvr32.exe' /s "%WINDIR%\Downloaded Program Files\icbcgm_MWusbkey_64.dll"' (with hidden window)
- '%WINDIR%\syswow64\regsvr32.exe' /s "%WINDIR%\Downloaded Program Files\icbc_mwusbkey.dll"' (with hidden window)
- '%WINDIR%\syswow64\regsvr32.exe' /s "%WINDIR%\Downloaded Program Files\icbcgm_MWusbkey.dll"' (with hidden window)
- '%ProgramFiles(x86)%\icbcebanktools\mingwah\mwicbcukeytoolu.exe' /RunMode AutoRun' (with hidden window)
- '<SYSTEM32>\regsvr32.exe' /s "%WINDIR%\Downloaded Program Files\icbc_mwusbkey_64.dll"
- '<SYSTEM32>\regsvr32.exe' /s "%WINDIR%\Downloaded Program Files\icbcgm_MWusbkey_64.dll"
- '%WINDIR%\syswow64\regsvr32.exe' /s "%WINDIR%\Downloaded Program Files\icbc_mwusbkey.dll"
- '%WINDIR%\syswow64\regsvr32.exe' /s "%WINDIR%\Downloaded Program Files\icbcgm_MWusbkey.dll"
- '<SYSTEM32>\taskeng.exe' {C6C1E741-940F-48A0-A195-D98BA6AF1694} S-1-5-21-1960123792-2022915161-3775307078-1001:zfngcimuxs\user:Interactive:[1]