Technical Information
- [<HKLM>\software\Wow6432Node\microsoft\windows\CurrentVersion\Run] 'OperatingSystem' = '%WINDIR%\NVDinsplay.exe'
- %WINDIR%\nvdinsplay.exe
- %ProgramFiles(x86)%\steam\winmm.dll
- <Current directory>\tem.vbs
- %ProgramFiles(x86)%\steam\winmm.dll
- %WINDIR%\nvdinsplay.exe
- <Current directory>\tem.vbs
- <Current directory>\tem.vbs
- 'a1##5.com':80
- DNS ASK a1##5.com
- '%WINDIR%\nvdinsplay.exe'
- '%WINDIR%\syswow64\wscript.exe' "<Current directory>\tem.vbs"