Technical Information
- '<SYSTEM32>\netsh.exe' advfirewall firewall add rule name="Driverupdater" dir=in action=allow program="\Package\data\dvu.exe" enable=yes
- %TEMP%\1.tmp\2.bat
- <Current directory>\dxupdate.tmp
- <Current directory>\conf.exe
- C:\Package\data\csrss.exe
- C:\Package\data\dvu.exe
- C:\Package\data\msvcp140.dll
- C:\Package\data\smss.exe
- C:\Package\data\vcruntime140.dll
- <Current directory>\conf.exe
- <Current directory>\dxupdate.tmp
- 'C:\Package\data\csrss.exe' -u %USERNAME% +r SeLockMemoryPrivilege
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\1.tmp\2.bat" <Full path to file>"
- '<SYSTEM32>\attrib.exe' +h "<Current directory>\conf.exe"
- '<SYSTEM32>\attrib.exe' +h "<Current directory>\dxupdate.tmp"
- '<SYSTEM32>\attrib.exe' +h \Package
- '<SYSTEM32>\expand.exe' "dxupdate.tmp" -F:* \Package\data\