
- #PORTABLE WONDERSHARE FANTASHOW PULS 3.0.4.40 DOWNLOAD#
- #PORTABLE WONDERSHARE FANTASHOW PULS 3.0.4.40 WINDOWS#
http:\\\dw\qbittorrent_4.0.2_setup.exe(qBittorrent). http:\\\dw\Silverlight.exe(Silverlight). http:\\\dw\DropboxInstaller.exe(Dropbox). http:\\\dw\tvpcstp.exe(TV Player Classic). #PORTABLE WONDERSHARE FANTASHOW PULS 3.0.4.40 DOWNLOAD#
http:\\\dw\idman630build7.exe(Internet Download Manager). http:\\\dw\MyPublicWiFi.exe(MyPublicWiFi). http:\\\dw\Thunderbird_Setup_52.4.0.exe(Mozilla Thunderbird). http:\\\dw\UC_Browser_7.exe(UC Browser). http:\\\ChromeSetup.exe(Google Chrome). http:\\\dw\YTDSetup.exe(YouTube Downloader). http:\\\MicrosoftEdgeSetupBeta.exe(Microsoft Edge). http:\\\dotNetFx45_Full_setup.exe(NET Framework). http:\\\dw\googledrivefilestream.exe(Google Drive). http:\\\dw\TunnelBear-Installer.exe(TunnelBear). http:\\\dw\OriginThinSetup.exe(Origin). http:\\\dw\YandexDiskSetupRu.exe(Yandex Disk). http:\\\dw\dmaster.exe(Download Master). http:\\\dw\UnityWebPlayer.exe(Unity Web Player). http:\\\dw\drugvokrug_win.exe(Drug Vokrug). http:\\\dw\VirtualRouterInstaller.zip(Virtual Router). http:\\\dw\vksaver-install.exe(VKSaver). http:\\\dw\IpTvPlayer-setup.exe(IP-TV Player). http:\\\dw\Google_Earth_Pro.exe(Google Earth). http:\\\dw\Firefox_Setup_55.0.3.exe(Mozilla Firefox). http:\\\TeamViewer_Setup.exe(TeamViewer). http:\\\install_flash_player-FireFoX.exe(Adobe Flash Player). http:\\\dw\EIE11_RU-RU_MCM_WIN7.EXE(Internet Explorer).
http:\\\torbrowser-install-9.0.2_ru.exe(Tor Browser). http:\\\dw\WhatsAppSetup.exe(WhatsApp). https:\\\d\29737\adguardInstaller.exe(Adguard). http:\\\dw\EpicInstaller-7.16.0.msi.zip(Epic Games Launcher). http:\\\TLauncher-2.66-Installer-0.5.2.exe(Minecraft TLauncher). http:\\\Installer_oscar.exe(Oscar Editor). http:\\\gg\gg_client.exe(Desktop Games). http:\\\PhysX-SystemSoftware.exe(NVIDIA PhysX System Software). It downloads the file from the following URL and renames the file when stored in the affected system: This Potentially Unwanted Application accesses the following websites to download files: It adds the following mutexes to ensure that only one of its copies runs at any one time: #PORTABLE WONDERSHARE FANTASHOW PULS 3.0.4.40 WINDOWS#
(Note: %User Temp% is the current user's Temp folder, which is usually C:\Documents and Settings\\AppData\Local\Temp on Windows Vista, 7, 8, 8.1, 2008(64-bit), 2012(64-bit) and 10(64-bit).)
%User Temp%\msetup\msetup.json → log containing program events. %User Temp%\multi_setup.log → contains download config chosen. This Potentially Unwanted Application drops the following files:
This Potentially Unwanted Application arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites. Payload: Connects to URLs/IPs, Displays windows