Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\acedrv11] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\acedrv11] 'ImagePath' = '<DRIVERS>\acedrv11.sys'
- %APPDATA%\ProtectDisc\pe17ec77b2.dll
- %TEMP%\Cab1.tmp
- %TEMP%\setup_pdd0.exe
- %TEMP%\nsm4.tmp
- %TEMP%\nsb5.tmp\acehelp.dll
- <DRIVERS>\acedrv11.sys
- %ProgramFiles%\ProtectDisc Driver Installer\uninstall_v11.exe
- %ALLUSERSPROFILE%\Documents\0000140A.LCS
- %TEMP%\Cab1.tmp
- %TEMP%\nsb5.tmp\acehelp.dll
- %TEMP%\setup_pdd0.exe
- 'wp#d':80
- 'download.windowsupdate.com':80
- 'cr#.##obalsign.net':80
- http://11#.#11.111.1/wpad.dat via wp#d
- http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt via download.windowsupdate.com
- http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab via download.windowsupdate.com
- http://cr#.##obalsign.net/Root.crl
- http://cr#.##obalsign.net/primobject.crl
- http://cr#.##obalsign.net/ObjectSign.crl
- DNS ASK wp#d
- DNS ASK www.download.windowsupdate.com
- DNS ASK cr#.##obalsign.net
- '%TEMP%\setup_pdd0.exe' /S