Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\abp480n5] 'Start' = '00000002'
- %WINDIR%\abp480n5s
- <DRIVERS>\SET1.tmp
- %WINDIR%\LastGood\TMP2.tmp
- <DRIVERS>\SET4.tmp
- <SYSTEM32>\dllcache\abp480n5.sys.new
- <Full path to file>
- <DRIVERS>\SET1.tmp
- from %WINDIR%\abp480n5s to <DRIVERS>\abp480n5.sys
- from %WINDIR%\LastGood\TMP2.tmp to %WINDIR%\LastGood\system32\drivers\abp480n5.sys
- from <DRIVERS>\abp480n5.sys to <DRIVERS>\OLD3.tmp
- <DRIVERS>\abp480n5.sys
- '<SYSTEM32>\cmd.exe' "ping localhost -n 8 & move /Y "%WINDIR%\abp480n5s" "<DRIVERS>\abp480n5.sys" & ping localhost -n 3 & net start abp480n5"
- '<SYSTEM32>\cmd.exe' /c "for /L %i in (1,1,100) do (del /F "<Full path to file>" & ping localhost -n 2 & if not exist "<Full path to file>" Exit 1)"
- '<SYSTEM32>\ping.exe' localhost -n 8
- '<SYSTEM32>\ping.exe' localhost -n 2
- '<SYSTEM32>\ping.exe' localhost -n 3
- '<SYSTEM32>\net.exe' start abp480n5
- '<SYSTEM32>\net1.exe' start abp480n5