Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\ISODrive] 'Start' = '00000001'
- [<HKLM>\SYSTEM\ControlSet001\Services\ISODrive] 'ImagePath' = '%WINDIR%\temp\ISODrive.sys'
- %TEMP%\aut1.tmp
- %WINDIR%\Temp\ISODrv64.sys
- %TEMP%\aut2.tmp
- %WINDIR%\Temp\IsoCmd.exe
- %TEMP%\aut3.tmp
- %WINDIR%\Temp\ISODrive.sys
- %WINDIR%\Temp\DRVinfo.txt
- %TEMP%\aut1.tmp
- %TEMP%\aut2.tmp
- %TEMP%\aut3.tmp
- '%WINDIR%\Temp\IsoCmd.exe' -n 1
- '%WINDIR%\Temp\IsoCmd.exe' -i
- '%WINDIR%\Temp\IsoCmd.exe' -p
- '<SYSTEM32>\cmd.exe' /C %WINDIR%\temp\isocmd.exe -n 1
- '<SYSTEM32>\cmd.exe' /C %WINDIR%\temp\isocmd.exe -i
- '<SYSTEM32>\cmd.exe' /C %WINDIR%\temp\isocmd.exe -p >%WINDIR%\temp\DRVinfo.txt