Technical Information
- '%WINDIR%\syswow64\taskkill.exe' /f /fi "imagename eq dms*"
- '%WINDIR%\syswow64\taskkill.exe' /F /IM splwow64.exe
- '%WINDIR%\syswow64\taskkill.exe' /F /IM spoolsv.exe
- '%WINDIR%\syswow64\net.exe' STOP "Spooler"
- <SYSTEM32>\spoolsv.exe
- %TEMP%\7zs7cae.tmp\addports.reg
- %CommonProgramFiles(x86)%\lacerte shared\pdf 4.0\install.ini
- %CommonProgramFiles(x86)%\lacerte shared\pdf 4.0\install.exe
- %CommonProgramFiles(x86)%\lacerte shared\pdf 4.0\dmsprnt.exe
- %CommonProgramFiles(x86)%\lacerte shared\pdf 4.0\cdintf64.dll
- %CommonProgramFiles(x86)%\lacerte shared\pdf 4.0\cdintf.dll
- %CommonProgramFiles(x86)%\lacerte shared\pdf 4.0\amyuni.inf
- %CommonProgramFiles(x86)%\lacerte shared\pdf 4.0\install.log
- %CommonProgramFiles(x86)%\lacerte shared\pdf 4.0\acpdfcrext.dll
- %CommonProgramFiles(x86)%\lacerte shared\pdf 4.0\acfpdfuiamd64.dll
- %CommonProgramFiles(x86)%\lacerte shared\pdf 4.0\acfpdfui.dll
- %CommonProgramFiles(x86)%\lacerte shared\pdf 4.0\acfpdfuamd64.dll
- %CommonProgramFiles(x86)%\lacerte shared\pdf 4.0\acfpdfu.dll
- %CommonProgramFiles(x86)%\lacerte shared\pdf 4.0\acfpdf.txt
- <SYSTEM32>\set7916.tmp
- %CommonProgramFiles(x86)%\lacerte shared\pdf 4.0\acpdfcrdb.dll
- %CommonProgramFiles(x86)%\lacerte shared\pdf 4.0\pdfcreactivex.dll
- %CommonProgramFiles(x86)%\lacerte shared\pdf 4.0\xmllite.dll
- %CommonProgramFiles(x86)%\lacerte shared\pdf 4.0\xmllite64.dll
- %CommonProgramFiles(x86)%\lacerte shared\pdf 4.5\pdfcreactivex.dll
- %CommonProgramFiles(x86)%\lacerte shared\pdf 4.5\install.log
- %CommonProgramFiles(x86)%\lacerte shared\pdf 4.5\install.ini
- %CommonProgramFiles(x86)%\lacerte shared\pdf 4.5\install.exe
- %CommonProgramFiles(x86)%\lacerte shared\pdf 4.5\dmsprnt.exe
- %CommonProgramFiles(x86)%\lacerte shared\pdf 4.5\cdintf64.dll
- %CommonProgramFiles(x86)%\lacerte shared\pdf 4.5\cdintf.dll
- %CommonProgramFiles(x86)%\lacerte shared\pdf 4.5\amyuni.inf
- %CommonProgramFiles(x86)%\lacerte shared\pdf 4.5\acpdfcrext.dll
- %CommonProgramFiles(x86)%\lacerte shared\pdf 4.5\acpdfcrdb.dll
- %CommonProgramFiles(x86)%\lacerte shared\pdf 4.5\acfpdfuiamd64.dll
- %CommonProgramFiles(x86)%\lacerte shared\pdf 4.5\acfpdfui.dll
- %CommonProgramFiles(x86)%\lacerte shared\pdf 4.5\acfpdfuamd64.dll
- %CommonProgramFiles(x86)%\lacerte shared\pdf 4.5\acfpdfu.dll
- %CommonProgramFiles(x86)%\lacerte shared\pdf 4.5\acfpdf.txt
- %WINDIR%\syswow64\set7712.tmp
- %CommonProgramFiles(x86)%\lacerte shared\pdf 4.5\xmllite.dll
- <SYSTEM32>\set586d.tmp
- <SYSTEM32>\spool\drivers\x64\3\new\cdintf450_64.dll
- %TEMP%\7zs7cae.tmp\amyuni450\acpdfcrext.dll
- %TEMP%\7zs7cae.tmp\amyuni450\acpdfcrdb.dll
- %TEMP%\7zs7cae.tmp\amyuni450\acfpdfuiamd64.dll
- %TEMP%\7zs7cae.tmp\amyuni450\acfpdfui.dll
- %TEMP%\7zs7cae.tmp\amyuni450\acfpdfuamd64.dll
- %TEMP%\7zs7cae.tmp\amyuni450\acfpdfu.dll
- %TEMP%\7zs7cae.tmp\amyuni450\cdintf.dll
- %TEMP%\7zs7cae.tmp\removenul.reg
- %TEMP%\7zs7cae.tmp\dmsprinter64.reg
- %TEMP%\7zs7cae.tmp\dmsprinter.reg
- %TEMP%\7zs7cae.tmp\amyuni450\install.log
- %TEMP%\7zs7cae.tmp\amyuni450\install.ini
- %TEMP%\7zs7cae.tmp\amyuni450\amyuni.inf
- %TEMP%\7zs7cae.tmp\amyuni450\acfpdf.txt
- %TEMP%\7zs7cae.tmp\lacertepdf.bat
- %TEMP%\7zs7cae.tmp\amyuni450\cdintf64.dll
- %TEMP%\7zs7cae.tmp\amyuni450\dmsprnt.exe
- %TEMP%\7zs7cae.tmp\amyuni450\install.exe
- <SYSTEM32>\spool\drivers\x64\3\new\acpdfui450.dll
- <SYSTEM32>\spool\drivers\x64\3\new\acpdf450.dll
- <SYSTEM32>\cdintf450_64.dll
- <SYSTEM32>\set25e8.tmp
- %WINDIR%\syswow64\cdintf450.dll
- %WINDIR%\syswow64\set20e8.tmp
- <SYSTEM32>\spool\drivers\x64\cdintf450_64.dll
- <SYSTEM32>\spool\drivers\x64\acfpdf.txt
- <SYSTEM32>\spool\drivers\x64\3\acfpdf.txt
- <SYSTEM32>\spool\drivers\x64\acpdfui450.dll
- <SYSTEM32>\spool\drivers\x64\acpdf450.dll
- nul
- %TEMP%\7zs7cae.tmp\amyuni450\xmllite64.dll
- %TEMP%\7zs7cae.tmp\amyuni450\xmllite.dll
- %TEMP%\7zs7cae.tmp\amyuni450\pdfcreactivex.dll
- %WINDIR%\syswow64\set5678.tmp
- %CommonProgramFiles(x86)%\lacerte shared\pdf 4.5\xmllite64.dll
- %TEMP%\7zs7cae.tmp\amyuni450\install.log
- %WINDIR%\syswow64\set20e8.tmp
- <SYSTEM32>\spool\drivers\x64\acpdf450.dll
- <SYSTEM32>\spool\drivers\x64\acpdfui450.dll
- <SYSTEM32>\spool\drivers\x64\acfpdf.txt
- <SYSTEM32>\spool\drivers\x64\cdintf450_64.dll
- %WINDIR%\syswow64\set5678.tmp
- %WINDIR%\syswow64\set7712.tmp
- from <SYSTEM32>\spool\drivers\x64\3\new\acpdf450.dll to <SYSTEM32>\spool\drivers\x64\3\acpdf450.dll
- from <SYSTEM32>\spool\drivers\x64\3\new\acpdfui450.dll to <SYSTEM32>\spool\drivers\x64\3\acpdfui450.dll
- from <SYSTEM32>\spool\drivers\x64\3\new\cdintf450_64.dll to <SYSTEM32>\spool\drivers\x64\3\cdintf450_64.dll
- %TEMP%\7zs7cae.tmp\amyuni450\install.log
- <SYSTEM32>\spool\drivers\x64\acpdf450.dll
- <SYSTEM32>\spool\drivers\x64\acpdfui450.dll
- <SYSTEM32>\spool\drivers\x64\acfpdf.txt
- <SYSTEM32>\spool\drivers\x64\cdintf450_64.dll
- ClassName: '' WindowName: ''
- ClassName: 'RegEdit_RegEdit' WindowName: ''
- '%TEMP%\7zs7cae.tmp\amyuni450\install.exe' -s "Lacerte PDF" -n "Intuit Inc." -O "NUL:" -c "07EFCDAB01000100CC84AC581282824C32A0944C3CE5CACA1509E3EDB3B8A8B75CE7ED37B486C9906518B76D6267D666CB1CA1196FBFF0A5D5511E001E4D"
- '%WINDIR%\syswow64\wscript.exe' /B /E:VBS "<SYSTEM32>\spool\DRIVERS\x64\3\ACFPDF.TXT" "Lacerte PDF"
- '%TEMP%\7zs7cae.tmp\amyuni450\install.exe' -s "Lacerte Tax PDF 4.0" -n "Intuit Inc." -O "NUL:" -c "07EFCDAB01000100CC84AC581282824C32A0944C3CE5CACA1509E3EDB3B8A8B75CE7ED37B486C9906518B76D6267D666CB1CA1196FBFF0A5D5511E001E4D"
- '%WINDIR%\syswow64\wscript.exe' /B /E:VBS "<SYSTEM32>\spool\DRIVERS\x64\3\ACFPDF.TXT" "Lacerte Tax PDF 4.0"
- '%TEMP%\7zs7cae.tmp\amyuni450\install.exe' -s "Lacerte Tax PDF 4.5" -n "Intuit Inc." -O "NUL:" -c "07EFCDAB01000100CC84AC581282824C32A0944C3CE5CACA1509E3EDB3B8A8B75CE7ED37B486C9906518B76D6267D666CB1CA1196FBFF0A5D5511E001E4D"
- '%WINDIR%\syswow64\wscript.exe' /B /E:VBS "<SYSTEM32>\spool\DRIVERS\x64\3\ACFPDF.TXT" "Lacerte Tax PDF 4.5"
- '%WINDIR%\syswow64\cmd.exe' /c "regsvr32 /s "<SYSTEM32>\cdintf450_64.dll""' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c .\LacertePDF.bat
- '<SYSTEM32>\spoolsv.exe'
- '%WINDIR%\syswow64\net1.exe' start "Spooler"
- '%WINDIR%\syswow64\net.exe' start "Spooler"
- '%WINDIR%\syswow64\regedit.exe' /s addports.reg
- '%WINDIR%\syswow64\regedit.exe' /s removenul.reg
- '%WINDIR%\syswow64\net1.exe' STOP "Spooler"
- '%WINDIR%\syswow64\ping.exe' -n 3 127.0.0.1
- '%WINDIR%\syswow64\cmd.exe' /c "regsvr32 /s "<SYSTEM32>\cdintf450_64.dll""
- '%WINDIR%\syswow64\ping.exe' -n 10 127.0.0.1
- '%WINDIR%\syswow64\cmd.exe' /S /D /c" echo WUDFHost.exe "
- '%WINDIR%\syswow64\cmd.exe' /S /D /c" echo winlogon.exe "
- '%WINDIR%\syswow64\find.exe' "tax.exe"
- '%WINDIR%\syswow64\cmd.exe' /S /D /c" echo wininit.exe "
- '%WINDIR%\syswow64\tasklist.exe' /nh /fi "imagename eq w*"
- '%WINDIR%\syswow64\cmd.exe' /c tasklist /nh /fi "imagename eq w*"
- '%WINDIR%\syswow64\ping.exe' -n 1 127.0.0.1
- '%WINDIR%\syswow64\cmd.exe' /S /D /c" echo WmiPrvSE.exe "
- '%WINDIR%\syswow64\regsvr32.exe' /s "<SYSTEM32>\cdintf450_64.dll"