Technical Information
- [<HKLM>\System\CurrentControlSet\Services\pptlcm] 'Start' = '00000001'
- [<HKLM>\System\CurrentControlSet\Services\pptlcm] 'ImagePath' = 'D:\Program Files (x86)\Oltpl\pptlcm.sys'
- [<HKLM>\System\CurrentControlSet\Services\msoprot] 'Start' = '00000001'
- [<HKLM>\System\CurrentControlSet\Services\msoprot] 'ImagePath' = 'system32\DRIVERS\msoprot.sys'
- [<HKLM>\System\CurrentControlSet\Services\msoprote] 'Start' = '00000001'
- [<HKLM>\System\CurrentControlSet\Services\msoprote] 'ImagePath' = 'system32\DRIVERS\msoprote.sys'
- 'pptlcm' D:\Program Files (x86)\Oltpl\pptlcm.sys
- D:\program files (x86)\oltpl\pptlcm.sys
- D:\program files (x86)\oltpl\oltpl.exe
- D:\program files (x86)\oltpl\uninstall.exe
- D:\program files (x86)\oltpl\client.dll
- D:\program files (x86)\oltpl\config.ini
- %WINDIR%\temp\udd11ac.tmp
- <DRIVERS>\msoprot.sys
- %WINDIR%\mscvcr90.dll
- %WINDIR%\temp\udd2ae7.tmp
- <DRIVERS>\msoprote.sys
- %WINDIR%\temp\udd44bf.tmp
- %WINDIR%\temp\udd11ac.tmp
- %WINDIR%\temp\udd2ae7.tmp
- %WINDIR%\temp\udd44bf.tmp
- D:\program files (x86)\oltpl\pptlcm.sys
- DNS ASK ms#.#ecbos.com
- DNS ASK ms#.##ctrbird.com
- DNS ASK ms#.#fdbns.info
- DNS ASK ms#.##bucnt.info
- DNS ASK ms#.##eyinoop.info
- DNS ASK ms#.##ctasm.info
- 'D:\program files (x86)\oltpl\oltpl.exe'