Technical Information
- [<HKLM>\System\CurrentControlSet\Services\HTTP SSL magener] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\HTTP SSL magener] 'ImagePath' = '%CommonProgramFiles%\Microsoft Shared\MSINFO\syskop.exe'
- 'HTTP SSL magener' %CommonProgramFiles%\Microsoft Shared\MSINFO\syskop.exe
- %WINDIR%\syswow64\svchost.exe
- %CommonProgramFiles%\microsoft shared\msinfo\syskop.exe
- %WINDIR%\syswow64\_syskop.exe
- %CommonProgramFiles%\microsoft shared\msinfo\redelbat.bat
- %CommonProgramFiles%\microsoft shared\msinfo\syskop.exe
- %WINDIR%\syswow64\_syskop.exe
- ClassName: 'MS_WINHELP' WindowName: ''
- '%CommonProgramFiles%\microsoft shared\msinfo\syskop.exe'
- '%WINDIR%\syswow64\cmd.exe' /c ""%CommonProgramFiles%\Microsoft Shared\MSINFO\ReDelBat.bat""' (with hidden window)
- '%WINDIR%\syswow64\mstsc.exe'
- '%WINDIR%\syswow64\svchost.exe'
- '%WINDIR%\syswow64\cmd.exe' /c ""%CommonProgramFiles%\Microsoft Shared\MSINFO\ReDelBat.bat""