The installer Inno Setup executes the following script.
This shows us that Crackonosh was packed in a password protected archive and unpacked in the process of installation.
Hunting led us to uncover uninstallation logs containing Crackonosh unpacking details when installed with cracked software. The only clue to what happened before the Maintenance.vbs creates this registry key and how the files appear on the computer of the victim is the removal of InstallWinSAT task in maintenance.vbs. It is easy to find out that serviceinstaller.exe is started from a registry key created by Maintenance.vbs.