Technical Information
- [HKLM\SYSTEM\CurrentControlSet\Services\ndespcbr] 'Start' = '00000002'
- [HKLM\SYSTEM\CurrentControlSet\Services\ndespcbr] 'ImagePath' = '"%WINDIR%\inf\<File name>.exe"'
- 'ndespcbr' %WINDIR%\inf\<File name>.exe
- %WINDIR%\inf\<File name>.exe
- %WINDIR%\inf\<File name>.exe
- '%WINDIR%\syswow64\cmd.exe' /c del "<Full path to file> " > nul' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c del "<Full path to file> " > nul