


This Potentially Unwanted Application accesses the following websites to download files: It adds the following mutexes to ensure that only one of its copies runs at any one time: (Note: %User Temp% is the current user's Temp folder, which is usually C:\Documents and Settings\\AppData\Local\Temp on Windows Vista, 7, 8, 8.1, 2008(64-bit), 2012(64-bit) and 10(64-bit).) %User Temp%\msetup\msetup.json → log containing program events.%User Temp%\multi_setup.log → contains download config chosen.This Potentially Unwanted Application drops the following files: This Potentially Unwanted Application arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites. Payload: Connects to URLs/IPs, Displays windows
