Technical Information
- [<HKLM>\System\CurrentControlSet\Control\Print\Providers\providortcbo] 'Name' = 'providortcbo.dll'
- [<HKLM>\System\CurrentControlSet\Services\n3d9.sys] 'ImagePath' = '<DRIVERS>\n3d9.sys'
- [<HKLM>\SYSTEM\CurrentControlSet\Services\{2E50535C4FD0770A6132592D66638925}] 'ImagePath' = '%TEMP%\B47.tmp'
- 'n3d9.sys' <DRIVERS>\n3d9.sys
- '{2E50535C4FD0770A6132592D66638925}' %TEMP%\B47.tmp
- %TEMP%\eb38.tmp
- %WINDIR%\syswow64\drivers\n3d9.sys
- %TEMP%\b47.tmp
- %WINDIR%\temp\uddf3f.tmp
- %TEMP%\172a.tmp
- %WINDIR%\syswow64\drivers\n3d9.sys
- %WINDIR%\temp\uddf3f.tmp
- %TEMP%\b47.tmp
- from %TEMP%\172a.tmp to %WINDIR%\syswow64\providortcbo.dll
- '%WINDIR%\syswow64\regsvr32.exe' /s %TEMP%\EB38.tmp