Technical Information
- [HKLM\System\CurrentControlSet\Services\acpidisk] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\acpidisk] 'ImagePath' = '<DRIVERS>\acpidisk.sys'
- 'acpidisk' <DRIVERS>\acpidisk.sys
- <Current directory>\dodolook022.exe
- <Current directory>\del32.bat
- %TEMP%\nso4b91.tmp
- %TEMP%\nso4b92.tmp\system.dll
- %TEMP%\55.exe
- %TEMP%\nsy5409.tmp\system.dll
- %TEMP%\dosssetup.dll
- %TEMP%\acpidisk.sys
- %WINDIR%\syswow64\drivers\acpidisk.sys
- %WINDIR%\syswow64\mscpx32r.det
- %TEMP%\nsy5409.tmp\system.dll
- %TEMP%\55.exe
- %TEMP%\acpidisk.sys
- %TEMP%\dosssetup.dll
- %TEMP%\nso4b92.tmp\system.dll
- '<Current directory>\dodolook022.exe'
- '%TEMP%\55.exe' 7022
- '%WINDIR%\syswow64\cmd.exe' /c ""<Current directory>\del32.bat" "
- '%WINDIR%\syswow64\cmd.exe' /c ""<Current directory>\del32.bat" "' (with hidden window)