Technical Information
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] 'Network Services' = '"<SYSTEM32>\kernel32.exe" /O0'
- [<HKLM>\System\CurrentControlSet\Services\Network Services] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\Network Services] 'ImagePath' = '"<SYSTEM32>\kernel32.exe" /srv /O0'
- <SYSTEM32>\kernel32.exe
- '<SYSTEM32>\kernel32.exe' /O0
- '<SYSTEM32>\kernel32.exe' /O0' (with hidden window)