Technical Information
- [<HKLM>\System\CurrentControlSet\Services\NalDrv] 'ImagePath' = '<Current directory>\NalDrv.sys'
- [<HKLM>\SYSTEM\CurrentControlSet\Services\0aVwqKeY] 'ImagePath' = '%TEMP%\0aVwqKeY'
- 'NalDrv' <Current directory>\NalDrv.sys
- '0aVwqKeY' %TEMP%\0aVwqKeY
- %TEMP%\w17pa78w.exe
- %TEMP%\drv64.dll
- <Current directory>\naldrv.sys
- %WINDIR%\temp\udd5bd5.tmp
- %TEMP%\0avwqkey
- %WINDIR%\temp\udd6c3b.tmp
- %WINDIR%\temp\udd5bd5.tmp
- <Current directory>\naldrv.sys
- %TEMP%\w17pa78w.exe
- %TEMP%\drv64.dll
- %WINDIR%\temp\udd6c3b.tmp
- <Current directory>\naldrv.sys
- '%TEMP%\w17pa78w.exe' -prv 0 -dse 0
- '%TEMP%\w17pa78w.exe' -prv 0 -dse 1
- '%WINDIR%\syswow64\cmd.exe' /c %TEMP%\w17pA78W.exe -prv 0 -dse 0' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c %TEMP%\w17pA78W.exe -prv 0 -dse 1' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c %TEMP%\w17pA78W.exe -prv 0 -dse 0
- '%WINDIR%\syswow64\cmd.exe' /c %TEMP%\w17pA78W.exe -prv 0 -dse 1