Technical Information
- [HKLM\System\CurrentControlSet\Services\WinDOSanquankZHI] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\WinDOSanquankZHI] 'ImagePath' = '%WINDIR%\WinDOSanquankZHI.exe'
- 'WinDOSanquankZHI' %WINDIR%\WinDOSanquankZHI.exe
- %WINDIR%\windosanquankzhi.exe
- %WINDIR%\windosanquankzhi.exe
- %WINDIR%\uninstal.bat
- %WINDIR%\windosanquankzhi.exe
- '%WINDIR%\windosanquankzhi.exe'
- '%WINDIR%\syswow64\cmd.exe' /c %WINDIR%\uninstal.BAT
- '%WINDIR%\syswow64\cmd.exe' /c %WINDIR%\uninstal.BAT' (with hidden window)