Technical Information
- [<HKLM>\Software\Classes\NSH4NSD\shell\Open\Command] '' = '"%WINDIR%\pcdrm\NSDHTMViewer.exe" "%1"'
- [<HKLM>\System\CurrentControlSet\Services\PcdrmSvc] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\PcdrmSvc] 'ImagePath' = '%WINDIR%\pcdrm\pcdrmsvc.exe'
- [<HKLM>\SYSTEM\CurrentControlSet\Services\NASCADRV64] 'ImagePath' = '%WINDIR%\pcdrm\NASCA64.sys'
- 'PcdrmSvc' %WINDIR%\pcdrm\pcdrmsvc.exe
- 'NASCADRV64' %WINDIR%\pcdrm\NASCA64.sys
- <SYSTEM32>\atl100.dll
- <SYSTEM32>\mfc100u.dll
- <SYSTEM32>\msvcp100.dll
- <SYSTEM32>\msvcr100.dll
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall add rule name="PC-DRM-P1" dir=in action=allow protocol=UDP localport=15035
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall add rule name="PC-DRM-P1" dir=out action=allow protocol=UDP localport=15035
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall add rule name="PC-DRM-P2" dir=in action=allow protocol=TCP localport=15036
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall add rule name="PC-DRM-P2" dir=out action=allow protocol=TCP localport=15036
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall add rule name="PC-DRM-P3" dir=in action=allow protocol=TCP localport=15035
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall add rule name="PC-DRM-P3" dir=out action=allow protocol=TCP localport=15035
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall add rule name="PC-DRM-P4" dir=in action=allow protocol=UDP localport=15036
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall add rule name="PC-DRM-P4" dir=out action=allow protocol=UDP localport=15036
- %TEMP%\nsreeec.tmp
- %WINDIR%\pcdrm\patch\nsr495e.sec
- %WINDIR%\pcdrm\patch\nsw492e.sec
- %WINDIR%\pcdrm\patch\nsh491e.sec
- %WINDIR%\pcdrm\patch\nsb4861.sec
- %WINDIR%\pcdrm\patch\nsm4851.sec
- %WINDIR%\pcdrm\patch\nsl4801.sec
- %WINDIR%\pcdrm\patch\nsl4800.sec
- %WINDIR%\pcdrm\patch\nsw47f0.sec
- %WINDIR%\pcdrm\patch\nsg47df.sec
- %WINDIR%\pcdrm\patch\nsl4713.sec
- %WINDIR%\pcdrm\patch\nsg46f3.sec
- %WINDIR%\pcdrm\patch\nsz4377.sec
- %WINDIR%\pcdrm\patch\nsn3ea4.sec
- %WINDIR%\pcdrm\patch\nsi3e84.sec
- %WINDIR%\pcdrm\patch\nsf3941.sec
- %WINDIR%\pcdrm\patch\nss3e73.sec
- %WINDIR%\pcdrm\patch\nss3e23.sec
- %WINDIR%\pcdrm\patch\nsc3e12.sec
- %WINDIR%\pcdrm\patch\nsc3dc3.sec
- %WINDIR%\pcdrm\patch\nss3d84.sec
- %WINDIR%\pcdrm\patch\nsh3cf6.sec
- %WINDIR%\pcdrm\patch\nsm3c78.sec
- %WINDIR%\pcdrm\patch\nsr3c48.sec
- %WINDIR%\pcdrm\patch\nsw3c18.sec
- %WINDIR%\pcdrm\patch\nsg3b1d.sec
- %WINDIR%\pcdrm\patch\nsr3b0d.sec
- %WINDIR%\pcdrm\patch\nsb3afc.sec
- %WINDIR%\pcdrm\patch\nsl3aeb.sec
- %WINDIR%\pcdrm\patch\nsl39b2.sec
- %WINDIR%\pcdrm\patch\nsq3982.sec
- %WINDIR%\pcdrm\patch\nsc3e62.sec
- %WINDIR%\pcdrm\patch\nsl3962.sec
- %WINDIR%\pcdrm\patch\nsh496f.sec
- %WINDIR%\pcdrm\patch\nsn58c2.sec
- %WINDIR%\pcdrm\patch\nsh63d0.sec
- %WINDIR%\pcdrm\nsd_uninstaller.exe
- %PROGRAMDATA%\microsoft\windows\start menu\programs\nsd\nsd_uninstaller.lnk
- %WINDIR%\pcdrm\patch\nsd8b4f.sec
- %WINDIR%\pcdrm\dump\20200617_pcdrmsvc.log
- %WINDIR%\pcdrm\policy\pcdrm.ini
- %TEMP%\nsgeefc.tmp\nsprocess.dll
- %WINDIR%\pcdrm\patch\nsl853.sec
- %WINDIR%\pcdrm\drmtmp\svctmp.reg
- %WINDIR%\temp\udda20f.tmp
- %WINDIR%\temp\uddb01a.tmp
- %WINDIR%\pcdrm\dump\20200617_nschim.log
- %WINDIR%\pcdrm\policy\drmsso.dat
- %WINDIR%\pcdrm\dump\20200617_nschill.log
- %WINDIR%\pcdrm\patch\nsm4990.sec
- %WINDIR%\pcdrm\patch\nsm498f.sec
- %WINDIR%\pcdrm\patch\nsn58c1.sec
- %WINDIR%\pcdrm\patch\nsk51bb.sec
- %WINDIR%\pcdrm\patch\nsk51ba.sec
- %WINDIR%\pcdrm\patch\nsv51aa.sec
- %WINDIR%\pcdrm\patch\nsm4a36.sec
- %WINDIR%\pcdrm\patch\nsm4a35.sec
- %WINDIR%\pcdrm\patch\nsm49e6.sec
- %WINDIR%\pcdrm\patch\nsx49d6.sec
- %WINDIR%\pcdrm\patch\nsx49d5.sec
- %WINDIR%\pcdrm\patch\nsh49c4.sec
- %WINDIR%\pcdrm\patch\nsr49b3.sec
- %WINDIR%\pcdrm\patch\nsr49b2.sec
- %WINDIR%\pcdrm\patch\nsc49a2.sec
- %WINDIR%\pcdrm\patch\nsc49a1.sec
- %WINDIR%\pcdrm\patch\nse5be0.sec
- %WINDIR%\pcdrm\patch\nsa38d3.sec
- %WINDIR%\pcdrm\patch\nsa38d2.sec
- %WINDIR%\pcdrm\patch\nsk38c1.sec
- %WINDIR%\pcdrm\patch\nsz410.sec
- %WINDIR%\pcdrm\patch\nsz40f.sec
- %WINDIR%\pcdrm\patch\nsu3ef.sec
- %WINDIR%\pcdrm\patch\nse3de.sec
- %WINDIR%\pcdrm\patch\nsp3ce.sec
- %WINDIR%\pcdrm\patch\nsk3ae.sec
- %WINDIR%\pcdrm\patch\nsp37e.sec
- %WINDIR%\pcdrm\patch\nsp37d.sec
- %WINDIR%\pcdrm\patch\nsu34d.sec
- %WINDIR%\pcdrm\patch\nsp32d.sec
- %WINDIR%\pcdrm\patch\nsj30c.sec
- %WINDIR%\pcdrm\patch\nso2dc.sec
- %WINDIR%\pcdrm\patch\nsy193.sec
- %WINDIR%\pcdrm\patch\nsu48f.sec
- %WINDIR%\pcdrm\patch\nsd163.sec
- %WINDIR%\pcdrm\patch\nsiffac.sec
- %WINDIR%\pcdrm\patch\nsifec1.sec
- %WINDIR%\pcdrm\patch\nsifec0.sec
- %WINDIR%\pcdrm\patch\nshfe22.sec
- %WINDIR%\pcdrm\patch\nssfdc4.sec
- %WINDIR%\pcdrm\nscinstlist.txt
- %TEMP%\nsgeefc.tmp\nscinstproc.dll
- %WINDIR%\syswow64\nsof621.sec
- %TEMP%\drmtmp\drminst.dll
- %TEMP%\msvcr100.dll
- %TEMP%\msvcp100.dll
- %TEMP%\mfc100u.dll
- %TEMP%\atl100.dll
- %TEMP%\nsgeefc.tmp\system.dll
- %WINDIR%\pcdrm\patch\nsyf5.sec
- %WINDIR%\pcdrm\patch\nsf51d.sec
- %WINDIR%\pcdrm\patch\nsu440.sec
- %WINDIR%\pcdrm\patch\nsp55c.sec
- %WINDIR%\pcdrm\patch\nsq3892.sec
- %WINDIR%\pcdrm\patch\nshafb.sec
- %WINDIR%\pcdrm\patch\nsv3814.sec
- %WINDIR%\pcdrm\patch\nsf3803.sec
- %WINDIR%\pcdrm\patch\nsu2a75.sec
- %WINDIR%\pcdrm\patch\nsp2a55.sec
- %WINDIR%\pcdrm\patch\nse288f.sec
- %WINDIR%\pcdrm\patch\nsz286f.sec
- %WINDIR%\pcdrm\patch\nse283f.sec
- %WINDIR%\pcdrm\patch\nsefc4.sec
- %WINDIR%\pcdrm\patch\nsidbf.sec
- %WINDIR%\pcdrm\pcdrmsvc.exe
- %WINDIR%\pcdrm\patch\nsscc4.sec
- %WINDIR%\pcdrm\patch\nsdc66.sec
- %WINDIR%\pcdrm\patch\nsdc17.sec
- %WINDIR%\pcdrm\patch\nsib99.sec
- %WINDIR%\pcdrm\patch\nsc9f1.sec
- %WINDIR%\pcdrm\patch\nsa5ea.sec
- %WINDIR%\pcdrm\patch\nsr963.sec
- %WINDIR%\pcdrm\patch\nsw933.sec
- %WINDIR%\pcdrm\patch\nsg8d4.sec
- %WINDIR%\pcdrm\patch\nsb8b4.sec
- %WINDIR%\pcdrm\patch\nsb8b3.sec
- %WINDIR%\pcdrm\patch\nsg883.sec
- %WINDIR%\pcdrm\dump\20200617_convini.log
- %WINDIR%\pcdrm\patch\nsb814.sec
- %WINDIR%\pcdrm\patch\nsg6ac.sec
- %WINDIR%\pcdrm\patch\nsl67c.sec
- %WINDIR%\pcdrm\patch\nsq64c.sec
- %WINDIR%\pcdrm\patch\nsl62c.sec
- %WINDIR%\pcdrm\patch\nsv61b.sec
- %WINDIR%\pcdrm\patch\nsq5fb.sec
- %WINDIR%\pcdrm\dump\20200617_drmmain.log
- %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\3842f86a08ee11b9b768828cf6f7225d_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
- %TEMP%\atl100.dll
- %TEMP%\mfc100u.dll
- %TEMP%\msvcp100.dll
- %TEMP%\msvcr100.dll
- %TEMP%\nsgeefc.tmp\nscinstproc.dll
- %TEMP%\nsgeefc.tmp\system.dll
- %TEMP%\nsgeefc.tmp\nsprocess.dll
- %WINDIR%\temp\udda20f.tmp
- %WINDIR%\temp\uddb01a.tmp
- from %WINDIR%\syswow64\nsof621.sec to %WINDIR%\syswow64\pcdistl.dll
- from %WINDIR%\pcdrm\patch\nsg47df.sec to %WINDIR%\pcdrm\nsd\policy\polcpsdk.dat
- from %WINDIR%\pcdrm\patch\nsl4713.sec to %WINDIR%\pcdrm\nsd\policy\polmatch.dat
- from %WINDIR%\pcdrm\patch\nsg46f3.sec to %WINDIR%\pcdrm\nsd\plugin\nativemsghost.exe
- from %WINDIR%\pcdrm\patch\nsz4377.sec to %WINDIR%\pcdrm\nsd\plugin\nativemsghost_manifest.json
- from %WINDIR%\pcdrm\patch\nsn3ea4.sec to %WINDIR%\pcdrm\nscpr.exe
- from %WINDIR%\pcdrm\patch\nsi3e84.sec to %WINDIR%\pcdrm\termbrk.exe
- from %WINDIR%\pcdrm\patch\nss3e73.sec to %WINDIR%\pcdrm\f_ntclr_64.dll
- from %WINDIR%\pcdrm\patch\nsc3e62.sec to %WINDIR%\pcdrm\nsdif4int64.dll
- from %WINDIR%\pcdrm\patch\nss3e23.sec to %WINDIR%\pcdrm\nsdif4doc64.dll
- from %WINDIR%\pcdrm\patch\nsc3e12.sec to %WINDIR%\pcdrm\chkswb64.dll
- from %WINDIR%\pcdrm\patch\nsc3dc3.sec to %WINDIR%\pcdrm\nsdcsprteng64.dll
- from %WINDIR%\pcdrm\patch\nsa38d2.sec to %WINDIR%\pcdrm\nscpe64.dll
- from %WINDIR%\pcdrm\patch\nss3d84.sec to %WINDIR%\pcdrm\nsdconvfiles.exe
- from %WINDIR%\pcdrm\patch\nsm3c78.sec to %WINDIR%\pcdrm\nsdconv64.dll
- from %WINDIR%\pcdrm\patch\nsr3c48.sec to %WINDIR%\pcdrm\drmlistv64.dll
- from %WINDIR%\pcdrm\patch\nsw3c18.sec to %WINDIR%\pcdrm\nsdlogininfo.exe
- from %WINDIR%\pcdrm\patch\nsg3b1d.sec to %WINDIR%\pcdrm\nsdclntif64.dll
- from %WINDIR%\pcdrm\patch\nsr3b0d.sec to %WINDIR%\pcdrm\nsdif4epe64.dll
- from %WINDIR%\pcdrm\patch\nsb3afc.sec to %WINDIR%\pcdrm\convini.exe
- from %WINDIR%\pcdrm\patch\nsl3aeb.sec to %WINDIR%\pcdrm\nscfw.exe
- from %WINDIR%\pcdrm\patch\nsl39b2.sec to %WINDIR%\pcdrm\msgproc.exe
- from %WINDIR%\pcdrm\patch\nsq3982.sec to %WINDIR%\pcdrm\drmmsgbx64.dll
- from %WINDIR%\pcdrm\patch\nsl3962.sec to %WINDIR%\pcdrm\contdpol64.dll
- from %WINDIR%\pcdrm\patch\nsf3941.sec to %WINDIR%\pcdrm\nscext264.dll
- from %WINDIR%\pcdrm\patch\nsh3cf6.sec to %WINDIR%\pcdrm\convfton.exe
- from %WINDIR%\pcdrm\patch\nsa38d3.sec to %WINDIR%\pcdrm\scwrppr64.dll
- from %WINDIR%\pcdrm\patch\nsw47f0.sec to %WINDIR%\pcdrm\nsd\policy\polcpinfo.dat
- from %WINDIR%\pcdrm\patch\nsr49b3.sec to %WINDIR%\pcdrm\nsd\conf\0000000000002282.conf
- from %WINDIR%\pcdrm\patch\nse5be0.sec to %WINDIR%\pcdrm\nsdicons01.dll
- from %WINDIR%\pcdrm\patch\nsn58c2.sec to %ProgramFiles(x86)%\nasca plugin for mozilla\npnascaplugin.dll
- from %WINDIR%\pcdrm\patch\nsn58c1.sec to %WINDIR%\pcdrm\policy\poldisk.dat
- from %WINDIR%\pcdrm\patch\nsk51bb.sec to %WINDIR%\pcdrm\policy\polhnc.dat
- from %WINDIR%\pcdrm\patch\nsk51ba.sec to %WINDIR%\pcdrm\policy\poldtmp.dat
- from %WINDIR%\pcdrm\patch\nsv51aa.sec to %WINDIR%\pcdrm\policy\polexp.dat
- from %WINDIR%\pcdrm\patch\nsm4a36.sec to %WINDIR%\pcdrm\policy\polnew.dat
- from %WINDIR%\pcdrm\patch\nsm4a35.sec to %WINDIR%\pcdrm\policy\polact.dat
- from %WINDIR%\pcdrm\patch\nsm49e6.sec to %WINDIR%\pcdrm\policy\poldlg.dat
- from %WINDIR%\pcdrm\patch\nsx49d6.sec to %WINDIR%\pcdrm\policy\pol3rd.dat
- from %WINDIR%\pcdrm\patch\nsx49d5.sec to %WINDIR%\pcdrm\nsd\conf\000000000000001e.conf
- from %WINDIR%\pcdrm\patch\nsl4801.sec to %WINDIR%\pcdrm\nsd\conf\000000000000004f.conf
- from %WINDIR%\pcdrm\patch\nsl4800.sec to %WINDIR%\pcdrm\nsd\policy\poliflist.dat
- from %WINDIR%\pcdrm\patch\nsr49b2.sec to %WINDIR%\pcdrm\nsd\conf\0000000000000511.conf
- from %WINDIR%\pcdrm\patch\nsc49a2.sec to %WINDIR%\pcdrm\nsd\conf\0000000000002546.conf
- from %WINDIR%\pcdrm\patch\nsc49a1.sec to %WINDIR%\pcdrm\nsd\conf\0000000000010501.conf
- from %WINDIR%\pcdrm\patch\nsm4990.sec to %WINDIR%\pcdrm\nsd\conf\0000000000011358.conf
- from %WINDIR%\pcdrm\patch\nsm498f.sec to %WINDIR%\pcdrm\nsd\conf\0000000000011114.conf
- from %WINDIR%\pcdrm\patch\nsh496f.sec to %WINDIR%\pcdrm\nsd\conf\0000000000010997.conf
- from %WINDIR%\pcdrm\patch\nsr495e.sec to %WINDIR%\pcdrm\nsd\conf\0000000000002515.conf
- from %WINDIR%\pcdrm\patch\nsw492e.sec to %WINDIR%\pcdrm\nsd\conf\0000000000002365.conf
- from %WINDIR%\pcdrm\patch\nsh491e.sec to %WINDIR%\pcdrm\nsd\conf\0000000000002257.conf
- from %WINDIR%\pcdrm\patch\nsb4861.sec to %WINDIR%\pcdrm\nsd\conf\0000000000000069.conf
- from %WINDIR%\pcdrm\patch\nsm4851.sec to %WINDIR%\pcdrm\nsd\conf\0000000000000056.conf
- from %WINDIR%\pcdrm\patch\nsh49c4.sec to %WINDIR%\pcdrm\nsd\conf\0000000000000835.conf
- from %WINDIR%\pcdrm\patch\nsk38c1.sec to %WINDIR%\pcdrm\nsdif4sp64.dll
- from %WINDIR%\pcdrm\patch\nsq3892.sec to %WINDIR%\pcdrm\nsdpnif64.dll
- from %WINDIR%\pcdrm\patch\nsv3814.sec to %WINDIR%\pcdrm\nbid64.dll
- from %WINDIR%\pcdrm\patch\nsf51d.sec to %WINDIR%\pcdrm\nsdclntif32.dll
- from %WINDIR%\pcdrm\patch\nsu48f.sec to %WINDIR%\pcdrm\drmutil2.dll
- from %WINDIR%\pcdrm\patch\nsu440.sec to %WINDIR%\pcdrm\drmmsgbx.dll
- from %WINDIR%\pcdrm\patch\nsz410.sec to %WINDIR%\pcdrm\contdpol.dll
- from %WINDIR%\pcdrm\patch\nsz40f.sec to %WINDIR%\pcdrm\nscext2.dll
- from %WINDIR%\pcdrm\patch\nsu3ef.sec to %WINDIR%\pcdrm\scwrppr.dll
- from %WINDIR%\pcdrm\patch\nse3de.sec to %WINDIR%\pcdrm\nscpe.dll
- from %WINDIR%\pcdrm\patch\nsp3ce.sec to %WINDIR%\pcdrm\nsdif4sp32.dll
- from %WINDIR%\pcdrm\patch\nsk3ae.sec to %WINDIR%\pcdrm\nsdpnif.dll
- from %WINDIR%\pcdrm\patch\nsp37e.sec to %WINDIR%\pcdrm\nbid.dll
- from %WINDIR%\pcdrm\patch\nsa5ea.sec to %WINDIR%\pcdrm\nsdconv.dll
- from %WINDIR%\pcdrm\patch\nsp37d.sec to %WINDIR%\pcdrm\nfd02.dll
- from %WINDIR%\pcdrm\patch\nsp32d.sec to %WINDIR%\pcdrm\nsdcpsdk.dll
- from %WINDIR%\pcdrm\patch\nsj30c.sec to %WINDIR%\pcdrm\nsdcsproccb.dll
- from %WINDIR%\pcdrm\patch\nso2dc.sec to %WINDIR%\pcdrm\drmnsc06.dll
- from %WINDIR%\pcdrm\patch\nsy193.sec to %WINDIR%\pcdrm\drmnsc05.dll
- from %WINDIR%\pcdrm\patch\nsd163.sec to %WINDIR%\pcdrm\nsccor06.dll
- from %WINDIR%\pcdrm\patch\nsyf5.sec to %WINDIR%\pcdrm\nsccor05.dll
- from %WINDIR%\pcdrm\patch\nsiffac.sec to %WINDIR%\pcdrm\nsccor03.dll
- from %WINDIR%\pcdrm\patch\nsifec1.sec to %WINDIR%\pcdrm\nsccor01.dll
- from %WINDIR%\pcdrm\patch\nsifec0.sec to %WINDIR%\pcdrm\nscbc.dll
- from %WINDIR%\pcdrm\patch\nshfe22.sec to %WINDIR%\pcdrm\drmrcstr.dat
- from %WINDIR%\pcdrm\patch\nssfdc4.sec to %WINDIR%\pcdrm\nasca_+sd_client open source license.pdf
- from %WINDIR%\pcdrm\patch\nsu34d.sec to %WINDIR%\pcdrm\nfd01.dll
- from %WINDIR%\pcdrm\patch\nsq5fb.sec to %WINDIR%\pcdrm\nsdif4epe32.dll
- from %WINDIR%\pcdrm\patch\nsp55c.sec to %WINDIR%\pcdrm\drmlistv.dll
- from %WINDIR%\pcdrm\patch\nsv61b.sec to %WINDIR%\pcdrm\chkepnfo.exe
- from %WINDIR%\pcdrm\patch\nsf3803.sec to %WINDIR%\pcdrm\nfd0264.dll
- from %WINDIR%\pcdrm\patch\nshafb.sec to %WINDIR%\pcdrm\nsccor0364.dll
- from %WINDIR%\pcdrm\patch\nsu2a75.sec to %WINDIR%\pcdrm\nfd0164.dll
- from %WINDIR%\pcdrm\patch\nsp2a55.sec to %WINDIR%\pcdrm\nsdcpsdk64.dll
- from %WINDIR%\pcdrm\patch\nse288f.sec to %WINDIR%\pcdrm\nsdcsproccb64.dll
- from %WINDIR%\pcdrm\patch\nsz286f.sec to %WINDIR%\pcdrm\drmnsc0664.dll
- from %WINDIR%\pcdrm\patch\nse283f.sec to %WINDIR%\pcdrm\drmnsc0564.dll
- from %WINDIR%\pcdrm\patch\nsefc4.sec to %WINDIR%\pcdrm\drmmain.exe
- from %WINDIR%\pcdrm\patch\nsidbf.sec to %WINDIR%\pcdrm\nschill.exe
- from %WINDIR%\pcdrm\patch\nsscc4.sec to %WINDIR%\pcdrm\convutil64.dll
- from %WINDIR%\pcdrm\patch\nsdc66.sec to %WINDIR%\pcdrm\drmnsc03.dll
- from %WINDIR%\pcdrm\patch\nsdc17.sec to %WINDIR%\pcdrm\nsccor0664.dll
- from %WINDIR%\pcdrm\patch\nsib99.sec to %WINDIR%\pcdrm\nsccor0564.dll
- from %WINDIR%\pcdrm\patch\nsc9f1.sec to %WINDIR%\pcdrm\nsccor0164.dll
- from %WINDIR%\pcdrm\patch\nsl62c.sec to %WINDIR%\pcdrm\convutil.dll
- from %WINDIR%\pcdrm\patch\nsr963.sec to %WINDIR%\pcdrm\nschim.exe
- from %WINDIR%\pcdrm\patch\nsw933.sec to %WINDIR%\pcdrm\nasca64.sys
- from %WINDIR%\pcdrm\patch\nsg8d4.sec to %WINDIR%\pcdrm\nasca32.sys
- from %WINDIR%\pcdrm\patch\nsb8b4.sec to %WINDIR%\pcdrm\nsdif4int32.dll
- from %WINDIR%\pcdrm\patch\nsb8b3.sec to %WINDIR%\pcdrm\nsdif4doc32.dll
- from %WINDIR%\pcdrm\patch\nsg883.sec to %WINDIR%\pcdrm\chkswb.dll
- from %WINDIR%\pcdrm\patch\nsl853.sec to %WINDIR%\pcdrm\nsdcsprteng.dll
- from %WINDIR%\pcdrm\patch\nsb814.sec to %WINDIR%\pcdrm\nedtray.exe
- from %WINDIR%\pcdrm\patch\nsg6ac.sec to %WINDIR%\pcdrm\nedlogin.exe
- from %WINDIR%\pcdrm\patch\nsl67c.sec to %WINDIR%\pcdrm\nsdhtmviewer.exe
- from %WINDIR%\pcdrm\patch\nsq64c.sec to %WINDIR%\pcdrm\f_ntclr.dll
- from %WINDIR%\pcdrm\patch\nsh63d0.sec to %WINDIR%\pcdrm\workpfv3.dll
- from %WINDIR%\pcdrm\patch\nsd8b4f.sec to %WINDIR%\pcdrm\nsdicons0164.dll
- %TEMP%\atl100.dll
- %TEMP%\mfc100u.dll
- %TEMP%\msvcp100.dll
- %TEMP%\msvcr100.dll
- '%WINDIR%\pcdrm\nscpr.exe'
- '%WINDIR%\pcdrm\drmmain.exe'
- '%WINDIR%\pcdrm\nschim.exe'
- '%WINDIR%\pcdrm\pcdrmsvc.exe' /install
- '%WINDIR%\pcdrm\convini.exe' /V=5.00 /B=2020021722
- '%WINDIR%\pcdrm\convini.exe' /SetDrmIcon
- '%WINDIR%\pcdrm\nschill.exe'
- '%WINDIR%\pcdrm\pcdrmsvc.exe'
- '%WINDIR%\pcdrm\nscfw.exe' 1592377721
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall add rule name="PC-DRM-P1" dir=in action=allow protocol=UDP localport=15035' (with hidden window)
- '%WINDIR%\pcdrm\nscpr.exe' ' (with hidden window)
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall add rule name="PC-DRM-P4" dir=out action=allow protocol=UDP localport=15036' (with hidden window)
- '%WINDIR%\pcdrm\nschim.exe' ' (with hidden window)
- '%WINDIR%\pcdrm\nscfw.exe' 1592377721' (with hidden window)
- '%WINDIR%\pcdrm\drmmain.exe' ' (with hidden window)
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall add rule name="PC-DRM-P2" dir=out action=allow protocol=TCP localport=15036' (with hidden window)
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall add rule name="PC-DRM-P3" dir=out action=allow protocol=TCP localport=15035' (with hidden window)
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall add rule name="PC-DRM-P3" dir=in action=allow protocol=TCP localport=15035' (with hidden window)
- '%WINDIR%\syswow64\net.exe' start PcdrmSvc' (with hidden window)
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall add rule name="PC-DRM-P2" dir=in action=allow protocol=TCP localport=15036' (with hidden window)
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall add rule name="PC-DRM-P1" dir=out action=allow protocol=UDP localport=15035' (with hidden window)
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall add rule name="PC-DRM-P4" dir=in action=allow protocol=UDP localport=15036' (with hidden window)
- '%WINDIR%\pcdrm\nschill.exe' ' (with hidden window)
- '%WINDIR%\syswow64\regsvr32.exe' /s "%WINDIR%\pcdrm\nsdicons01.dll"
- '%WINDIR%\syswow64\regsvr32.exe' /s "%WINDIR%\pcdrm\WorkPFV3.DLL"
- '<SYSTEM32>\regsvr32.exe' /s "%WINDIR%\pcdrm\nsdicons0164.dll"
- '%WINDIR%\syswow64\net.exe' start PcdrmSvc
- '%WINDIR%\syswow64\net1.exe' start PcdrmSvc