Technical Information
- [<HKLM>\System\CurrentControlSet\Services\system] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\system] 'ImagePath' = '<SYSTEM32>\system.exe -NetSata'
- 'system' <SYSTEM32>\system.exe -NetSata
- %WINDIR%\syswow64\system.exe
- %WINDIR%\syswow64\pzh.dat
- %WINDIR%\syswow64\system.dll
- %WINDIR%\syswow64\deleteme.bat
- ClassName: 'WJD2006' WindowName: 'mybr'
- '%WINDIR%\syswow64\system.exe' -NetSata
- '%WINDIR%\syswow64\cmd.exe' /c <SYSTEM32>\Deleteme.bat' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c <SYSTEM32>\Deleteme.bat