Technical Information
- [<HKLM>\System\CurrentControlSet\Services\RSBASTOR] 'ImagePath' = 'system32\DRIVERS\RtsBaStor.sys'
- %TEMP%\7zsc27204cf\04creader\apbin\config.ini
- <DRIVERS>\rtsb12bf.rra
- %ProgramFiles(x86)%\realtek\realtek pcie card reader\rtsb12bf.rra
- %ProgramFiles(x86)%\realtek\realtek pcie card reader\rtsb1157.rra
- %ProgramFiles(x86)%\realtek\realtek pcie card reader\rtsb1138.rra
- %ProgramFiles(x86)%\realtek\realtek pcie card reader\revc1119.rra
- %ProgramFiles(x86)%\realtek\realtek pcie card reader\rscr1119.rra
- %ProgramFiles(x86)%\realtek\realtek pcie card reader\conf12ce.rra
- %ProgramFiles(x86)%\realtek\realtek pcie card reader\rico108c.rra
- %TEMP%\{2c5b734d-c535-4a58-982f-1c275a06dda9}\{c1594429-8296-4652-bf54-9dbe4932a44c}\defaef29.rra
- %TEMP%\{2c5b734d-c535-4a58-982f-1c275a06dda9}\{c1594429-8296-4652-bf54-9dbe4932a44c}\isrtef1a.rra
- %TEMP%\{2c5b734d-c535-4a58-982f-1c275a06dda9}\{c1594429-8296-4652-bf54-9dbe4932a44c}\strief0a.rra
- %TEMP%\{2c5b734d-c535-4a58-982f-1c275a06dda9}\isbeef0a.rra
- %TEMP%\{2c5b734d-c535-4a58-982f-1c275a06dda9}\{c1594429-8296-4652-bf54-9dbe4932a44c}\difxef0a.rra
- %TEMP%\{2c5b734d-c535-4a58-982f-1c275a06dda9}\{c1594429-8296-4652-bf54-9dbe4932a44c}\fonteefa.rra
- %TEMP%\{2c5b734d-c535-4a58-982f-1c275a06dda9}\{c1594429-8296-4652-bf54-9dbe4932a44c}\_isref29.rra
- %ProgramFiles(x86)%\realtek\realtek pcie card reader\disp12de.rra
- %ProgramFiles(x86)%\realtek\realtek pcie card reader\rmbc12de.rra
- %ProgramFiles(x86)%\realtek\realtek pcie card reader\sdrt132c.rra
- %WINDIR%\syswow64\sda\sdrt5834.rra
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\oem2.cat
- %WINDIR%\temp\udd2906.tmp
- %TEMP%\{695b3478-4fe3-45cd-8241-3919c3ec766c}\set2772.tmp
- %TEMP%\{695b3478-4fe3-45cd-8241-3919c3ec766c}\set258d.tmp
- %TEMP%\{695b3478-4fe3-45cd-8241-3919c3ec766c}\set234a.tmp
- %TEMP%\{695b3478-4fe3-45cd-8241-3919c3ec766c}\set2220.tmp
- %ProgramFiles(x86)%\installshield installation information\{c1594429-8296-4652-bf54-9dbe4932a44c}\setup.ini
- %ProgramFiles(x86)%\installshield installation information\{c1594429-8296-4652-bf54-9dbe4932a44c}\setu162a.rra
- %ProgramFiles(x86)%\installshield installation information\{c1594429-8296-4652-bf54-9dbe4932a44c}\setu160a.rra
- %ProgramFiles(x86)%\installshield installation information\{c1594429-8296-4652-bf54-9dbe4932a44c}\isse15cc.rra
- %ProgramFiles(x86)%\installshield installation information\{c1594429-8296-4652-bf54-9dbe4932a44c}\_set15bc.rra
- %ProgramFiles(x86)%\installshield installation information\{c1594429-8296-4652-bf54-9dbe4932a44c}\setu159d.rra
- %ProgramFiles(x86)%\installshield installation information\{c1594429-8296-4652-bf54-9dbe4932a44c}\data14f1.rra
- %ProgramFiles(x86)%\installshield installation information\{c1594429-8296-4652-bf54-9dbe4932a44c}\layo14f1.rra
- %TEMP%\{2c5b734d-c535-4a58-982f-1c275a06dda9}\dotneefa.rra
- %ProgramFiles(x86)%\realtek\realtek pcie card reader\rmb.log
- %TEMP%\{2c5b734d-c535-4a58-982f-1c275a06dda9}\coreeeeb.rra
- %TEMP%\{2c5b734d-c535-4a58-982f-1c275a06dda9}\{c1594429-8296-4652-bf54-9dbe4932a44c}\setueecb.rra
- %TEMP%\7zsc27204cf\04creader\usetup.iss
- %TEMP%\7zsc27204cf\04creader\setup.iss
- %TEMP%\7zsc27204cf\04creader\setup.inx
- %TEMP%\7zsc27204cf\04creader\setup.ini
- %TEMP%\7zsc27204cf\04creader\readme.txt
- %TEMP%\7zsc27204cf\04creader\layout.bin
- %TEMP%\7zsc27204cf\04creader\apbin\rmbchange_pcie.exe
- %TEMP%\7zsc27204cf\04creader\driverbin_64bit\rtsbastormsi.inf
- %TEMP%\7zsc27204cf\04creader\driverbin_32bit\rtsbastormsi.inf
- %TEMP%\7zsc27204cf\04creader\driverbin_32bit\rtsbastor.cat
- %TEMP%\7zsc27204cf\04creader\data2.cab
- %TEMP%\7zsc27204cf\04creader\data1.hdr
- %TEMP%\7zsc27204cf\04creader\data1.cab
- %TEMP%\7zsc27204cf\04creader\apbin\displayicon.ico
- %TEMP%\7zsc27204cf\04creader\driverbin_64bit\rtsbastor.cat
- %TEMP%\7zsc27204cf\04creader\apbin\sdrtcprm.dll
- %TEMP%\7zsc27204cf\04creader\apbin_32bit\riconman.exe
- %TEMP%\7zsc27204cf\04creader\apbin_32bit\rscrlib.dll
- %TEMP%\ee10.rra
- %TEMP%\{d6b87d5f-ad51-4fdf-8d1f-726d43b99072}\setup.ini
- %TEMP%\{d6b87d5f-ad51-4fdf-8d1f-726d43b99072}\_setup.dll
- %TEMP%\7zsc27204cf\04creader\_setup.dll
- %TEMP%\7zsc27204cf\04creader\setup.exe
- %TEMP%\7zsc27204cf\04creader\issetup.dll
- %TEMP%\7zsc27204cf\04creader\driverbin_64bit\rtsbastoricon.dll
- %TEMP%\7zsc27204cf\04creader\driverbin_64bit\rtsbastor.sys
- %TEMP%\7zsc27204cf\04creader\driverbin_64bit\revcon.exe
- %TEMP%\7zsc27204cf\04creader\driverbin_32bit\sdrtcprm.dll
- %TEMP%\7zsc27204cf\04creader\driverbin_32bit\rtsbastoricon.dll
- %TEMP%\7zsc27204cf\04creader\driverbin_32bit\rtsbastor.sys
- %TEMP%\7zsc27204cf\04creader\driverbin_32bit\revcon.exe
- %TEMP%\7zsc27204cf\04creader\apbin_64bit\rscrlib.dll
- %TEMP%\7zsc27204cf\04creader\apbin_64bit\riconman.exe
- %TEMP%\{2c5b734d-c535-4a58-982f-1c275a06dda9}\{c1594429-8296-4652-bf54-9dbe4932a44c}\liceeeeb.rra
- %ProgramFiles(x86)%\realtek\realtek pcie card reader\config.ini
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\oem2.cat
- %WINDIR%\temp\udd2906.tmp
- %TEMP%\{695b3478-4fe3-45cd-8241-3919c3ec766c}\rtsbastor.cat
- %TEMP%\{695b3478-4fe3-45cd-8241-3919c3ec766c}\rtsbastor.sys
- %TEMP%\{695b3478-4fe3-45cd-8241-3919c3ec766c}\rtsbastoricon.dll
- %TEMP%\{695b3478-4fe3-45cd-8241-3919c3ec766c}\rtsbastormsi.inf
- from %TEMP%\{2c5b734d-c535-4a58-982f-1c275a06dda9}\{c1594429-8296-4652-bf54-9dbe4932a44c}\setueecb.rra to %TEMP%\{2c5b734d-c535-4a58-982f-1c275a06dda9}\{c1594429-8296-4652-bf54-9dbe4932a44c}\setup.inx
- from %ProgramFiles(x86)%\realtek\realtek pcie card reader\rmbc12de.rra to %ProgramFiles(x86)%\realtek\realtek pcie card reader\rmbchange_pcie.exe
- from %ProgramFiles(x86)%\realtek\realtek pcie card reader\sdrt132c.rra to %ProgramFiles(x86)%\realtek\realtek pcie card reader\sdrtcprm.dll
- from %ProgramFiles(x86)%\installshield installation information\{c1594429-8296-4652-bf54-9dbe4932a44c}\layo14f1.rra to %ProgramFiles(x86)%\installshield installation information\{c1594429-8296-4652-bf54-9dbe4932a44c}\layout.bin
- from %ProgramFiles(x86)%\installshield installation information\{c1594429-8296-4652-bf54-9dbe4932a44c}\data14f1.rra to %ProgramFiles(x86)%\installshield installation information\{c1594429-8296-4652-bf54-9dbe4932a44c}\data1.hdr
- from %ProgramFiles(x86)%\installshield installation information\{c1594429-8296-4652-bf54-9dbe4932a44c}\data14f1.rra to %ProgramFiles(x86)%\installshield installation information\{c1594429-8296-4652-bf54-9dbe4932a44c}\data1.cab
- from %ProgramFiles(x86)%\realtek\realtek pcie card reader\conf12ce.rra to %ProgramFiles(x86)%\realtek\realtek pcie card reader\config.ini
- from %ProgramFiles(x86)%\realtek\realtek pcie card reader\disp12de.rra to %ProgramFiles(x86)%\realtek\realtek pcie card reader\displayicon.ico
- from %ProgramFiles(x86)%\installshield installation information\{c1594429-8296-4652-bf54-9dbe4932a44c}\setu159d.rra to %ProgramFiles(x86)%\installshield installation information\{c1594429-8296-4652-bf54-9dbe4932a44c}\setup.exe
- from %ProgramFiles(x86)%\installshield installation information\{c1594429-8296-4652-bf54-9dbe4932a44c}\setu160a.rra to %ProgramFiles(x86)%\installshield installation information\{c1594429-8296-4652-bf54-9dbe4932a44c}\setup.inx
- from %ProgramFiles(x86)%\installshield installation information\{c1594429-8296-4652-bf54-9dbe4932a44c}\setu162a.rra to %ProgramFiles(x86)%\installshield installation information\{c1594429-8296-4652-bf54-9dbe4932a44c}\setup.ini
- from %TEMP%\{695b3478-4fe3-45cd-8241-3919c3ec766c}\set2220.tmp to %TEMP%\{695b3478-4fe3-45cd-8241-3919c3ec766c}\rtsbastormsi.inf
- from %TEMP%\{695b3478-4fe3-45cd-8241-3919c3ec766c}\set234a.tmp to %TEMP%\{695b3478-4fe3-45cd-8241-3919c3ec766c}\rtsbastoricon.dll
- from %TEMP%\{695b3478-4fe3-45cd-8241-3919c3ec766c}\set258d.tmp to %TEMP%\{695b3478-4fe3-45cd-8241-3919c3ec766c}\rtsbastor.cat
- from %ProgramFiles(x86)%\installshield installation information\{c1594429-8296-4652-bf54-9dbe4932a44c}\_set15bc.rra to %ProgramFiles(x86)%\installshield installation information\{c1594429-8296-4652-bf54-9dbe4932a44c}\_setup.dll
- from %ProgramFiles(x86)%\installshield installation information\{c1594429-8296-4652-bf54-9dbe4932a44c}\isse15cc.rra to %ProgramFiles(x86)%\installshield installation information\{c1594429-8296-4652-bf54-9dbe4932a44c}\issetup.dll
- from <DRIVERS>\rtsb12bf.rra to <DRIVERS>\rtsbastor.sys
- from %ProgramFiles(x86)%\realtek\realtek pcie card reader\rtsb12bf.rra to %ProgramFiles(x86)%\realtek\realtek pcie card reader\rtsbastormsi.inf
- from %ProgramFiles(x86)%\realtek\realtek pcie card reader\rtsb1157.rra to %ProgramFiles(x86)%\realtek\realtek pcie card reader\rtsbastoricon.dll
- from %TEMP%\{2c5b734d-c535-4a58-982f-1c275a06dda9}\coreeeeb.rra to %TEMP%\{2c5b734d-c535-4a58-982f-1c275a06dda9}\corecomp.ini
- from %TEMP%\{2c5b734d-c535-4a58-982f-1c275a06dda9}\dotneefa.rra to %TEMP%\{2c5b734d-c535-4a58-982f-1c275a06dda9}\dotnetinstaller.exe
- from %TEMP%\{2c5b734d-c535-4a58-982f-1c275a06dda9}\{c1594429-8296-4652-bf54-9dbe4932a44c}\fonteefa.rra to %TEMP%\{2c5b734d-c535-4a58-982f-1c275a06dda9}\{c1594429-8296-4652-bf54-9dbe4932a44c}\fontdata.ini
- from %TEMP%\{2c5b734d-c535-4a58-982f-1c275a06dda9}\{c1594429-8296-4652-bf54-9dbe4932a44c}\difxef0a.rra to %TEMP%\{2c5b734d-c535-4a58-982f-1c275a06dda9}\{c1594429-8296-4652-bf54-9dbe4932a44c}\difxdata.ini
- from %TEMP%\{2c5b734d-c535-4a58-982f-1c275a06dda9}\isbeef0a.rra to %TEMP%\{2c5b734d-c535-4a58-982f-1c275a06dda9}\isbew64.exe
- from %TEMP%\{2c5b734d-c535-4a58-982f-1c275a06dda9}\{c1594429-8296-4652-bf54-9dbe4932a44c}\strief0a.rra to %TEMP%\{2c5b734d-c535-4a58-982f-1c275a06dda9}\{c1594429-8296-4652-bf54-9dbe4932a44c}\stringtable-0009-english.ips
- from %TEMP%\{2c5b734d-c535-4a58-982f-1c275a06dda9}\{c1594429-8296-4652-bf54-9dbe4932a44c}\liceeeeb.rra to %TEMP%\{2c5b734d-c535-4a58-982f-1c275a06dda9}\{c1594429-8296-4652-bf54-9dbe4932a44c}\license.rtf
- from %TEMP%\{2c5b734d-c535-4a58-982f-1c275a06dda9}\{c1594429-8296-4652-bf54-9dbe4932a44c}\isrtef1a.rra to %TEMP%\{2c5b734d-c535-4a58-982f-1c275a06dda9}\{c1594429-8296-4652-bf54-9dbe4932a44c}\isrt.dll
- from %TEMP%\{2c5b734d-c535-4a58-982f-1c275a06dda9}\{c1594429-8296-4652-bf54-9dbe4932a44c}\_isref29.rra to %TEMP%\{2c5b734d-c535-4a58-982f-1c275a06dda9}\{c1594429-8296-4652-bf54-9dbe4932a44c}\_isres.dll
- from %ProgramFiles(x86)%\realtek\realtek pcie card reader\rico108c.rra to %ProgramFiles(x86)%\realtek\realtek pcie card reader\riconman.exe
- from %ProgramFiles(x86)%\realtek\realtek pcie card reader\rscr1119.rra to %ProgramFiles(x86)%\realtek\realtek pcie card reader\rscrlib.dll
- from %ProgramFiles(x86)%\realtek\realtek pcie card reader\revc1119.rra to %ProgramFiles(x86)%\realtek\realtek pcie card reader\revcon.exe
- from %ProgramFiles(x86)%\realtek\realtek pcie card reader\rtsb1138.rra to %ProgramFiles(x86)%\realtek\realtek pcie card reader\rtsbastor.cat
- from %ProgramFiles(x86)%\realtek\realtek pcie card reader\rtsb1138.rra to %ProgramFiles(x86)%\realtek\realtek pcie card reader\rtsbastor.sys
- from %TEMP%\{2c5b734d-c535-4a58-982f-1c275a06dda9}\{c1594429-8296-4652-bf54-9dbe4932a44c}\defaef29.rra to %TEMP%\{2c5b734d-c535-4a58-982f-1c275a06dda9}\{c1594429-8296-4652-bf54-9dbe4932a44c}\default.pal
- from %TEMP%\{695b3478-4fe3-45cd-8241-3919c3ec766c}\set2772.tmp to %TEMP%\{695b3478-4fe3-45cd-8241-3919c3ec766c}\rtsbastor.sys
- from %WINDIR%\syswow64\sda\sdrt5834.rra to %WINDIR%\syswow64\sda\sdrtcprm.dll
- %ProgramFiles(x86)%\realtek\realtek pcie card reader\rtsb1138.rra
- %ProgramFiles(x86)%\installshield installation information\{c1594429-8296-4652-bf54-9dbe4932a44c}\data14f1.rra
- '%TEMP%\7zsc27204cf\04creader\setup.exe'
- '%TEMP%\{2c5b734d-c535-4a58-982f-1c275a06dda9}\isbew64.exe' {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{BB43F673-C0AB-416B-A558-20A10345344F}
- '%ProgramFiles(x86)%\realtek\realtek pcie card reader\revcon.exe' RS_dp_add RtsBaStorMSI.inf
- '%ProgramFiles(x86)%\realtek\realtek pcie card reader\revcon.exe' RS_update RtsBaStorMSI.inf PCI\VEN_10EC&DEV_5289&CC_FF00
- '%ProgramFiles(x86)%\realtek\realtek pcie card reader\revcon.exe' RS_remove PCI\VEN_10EC&DEV_5289&CC_FF00
- '%ProgramFiles(x86)%\realtek\realtek pcie card reader\revcon.exe' RS_update RtsBaStorMSI.inf PCI\VEN_10EC&DEV_5286&CC_FF00
- '%ProgramFiles(x86)%\realtek\realtek pcie card reader\revcon.exe' RS_remove PCI\VEN_10EC&DEV_5286&CC_FF00
- '%ProgramFiles(x86)%\realtek\realtek pcie card reader\rmbchange_pcie.exe' /install
- '%ProgramFiles(x86)%\realtek\realtek pcie card reader\revcon.exe' RS_dp_add RtsBaStorMSI.inf' (with hidden window)
- '%ProgramFiles(x86)%\realtek\realtek pcie card reader\revcon.exe' RS_update RtsBaStorMSI.inf PCI\VEN_10EC&DEV_5289&CC_FF00' (with hidden window)
- '%ProgramFiles(x86)%\realtek\realtek pcie card reader\revcon.exe' RS_remove PCI\VEN_10EC&DEV_5289&CC_FF00' (with hidden window)
- '%ProgramFiles(x86)%\realtek\realtek pcie card reader\revcon.exe' RS_update RtsBaStorMSI.inf PCI\VEN_10EC&DEV_5286&CC_FF00' (with hidden window)
- '%ProgramFiles(x86)%\realtek\realtek pcie card reader\revcon.exe' RS_remove PCI\VEN_10EC&DEV_5286&CC_FF00' (with hidden window)
- '%ProgramFiles(x86)%\realtek\realtek pcie card reader\rmbchange_pcie.exe' /install' (with hidden window)