Technical Information
- [HKLM\System\CurrentControlSet\Services\NalDrv] 'ImagePath' = '<Current directory>\NalDrv.sys'
- [HKLM\System\CurrentControlSet\Services\PROCEXP152] 'ImagePath' = '<DRIVERS>\PROCEXP152.sys'
- 'NalDrv' <Current directory>\NalDrv.sys
- 'PROCEXP152' <DRIVERS>\PROCEXP152.sys
- %WINDIR%\softwaredistribution\download\taigei64.dll
- %WINDIR%\softwaredistribution\download\drv64.dll
- %WINDIR%\softwaredistribution\download\78rgey1hk6f7jej.sys
- %WINDIR%\softwaredistribution\download\e6k2u74b4acxxoz.exe
- <Current directory>\naldrv.sys
- <DRIVERS>\procexp152.sys
- <DRIVERS>\procexp152.sys
- %WINDIR%\softwaredistribution\download\78rgey1hk6f7jej.sys
- %WINDIR%\softwaredistribution\download\e6k2u74b4acxxoz.exe
- <Current directory>\naldrv.sys
- '%WINDIR%\softwaredistribution\download\e6k2u74b4acxxoz.exe' -map %WINDIR%\SoftwareDistribution\Download\78rgey1hk6f7jej.sys
- '%WINDIR%\softwaredistribution\download\e6k2u74b4acxxoz.exe' -map %WINDIR%\SoftwareDistribution\Download\78rgey1hk6f7jej.sys' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c color a
- '<SYSTEM32>\cmd.exe' /c cls
- '<SYSTEM32>\cmd.exe' /c color c