Technical Information
- [HKLM\System\CurrentControlSet\Services\wcztj93] 'ImagePath' = '<DRIVERS>\wcztj93.sys'
- 'wcztj93' <DRIVERS>\wcztj93.sys
- %TEMP%\polive\windows\b.sys
- %TEMP%\polive\windows\stab.dll
- %TEMP%\polive\windows\winb.dll
- %TEMP%\polive\setup.exe
- %WINDIR%\syswow64\wintj93.dll
- %WINDIR%\syswow64\drivers\wcztj93.sys
- %WINDIR%\syswow64\wcztj93.dll
- %TEMP%\polive\setup.exe
- %TEMP%\polive\windows\b.sys
- %TEMP%\polive\windows\stab.dll
- %TEMP%\polive\windows\winb.dll
- '%TEMP%\polive\setup.exe' <File name> /s
- '%WINDIR%\syswow64\regsvr32.exe' /s "<SYSTEM32>\wintj93.dll"
- '%WINDIR%\syswow64\rundll32.exe' "<SYSTEM32>\wcztj93.dll",StartByHostEx
- '%WINDIR%\syswow64\regsvr32.exe' /s "<SYSTEM32>\wintj93.dll"' (with hidden window)
- '%WINDIR%\syswow64\rundll32.exe' "<SYSTEM32>\wcztj93.dll",StartByHostEx' (with hidden window)