Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\ACEDRV07] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\ACEDRV07] 'ImagePath' = '<DRIVERS>\ACEDRV07.sys'
- %TEMP%\a001.tmp
- <DRIVERS>\ACEDRV07.sys
- <SYSTEM32>\RSA32_16.DLL
- %ALLUSERSPROFILE%\Documents\0000027A.LCS
- 'pr###ctdisc.com':80
- http://www.pr###ctdisc.com/protectdisc/Admin.asmx via pr###ctdisc.com
- DNS ASK www.pr###ctdisc.com
- '<Full path to file>'