Technical Information
- [HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'MyStartupApp' = '<PATH_SAMPLE>_3205.exe'
- %APPDATA%\microsoft\windows\start menu\programs\startup\mystartupapp.lnk
- %ProgramFiles%\windowsapps\microsoft.xboxgamingoverlay_2.26.14003.0_x64__8wekyb3d8bbwe\gamebar.exe
- <PATH_SAMPLE>_3205.exe
- %WINDIR%\softwaredistribution\sls\9482f4b4-e343-43b6-b170-9a65bc822c77\sls.cab
- %WINDIR%\softwaredistribution\sls\9482f4b4-e343-43b6-b170-9a65bc822c77\tmpc5c1.tmp
- %WINDIR%\softwaredistribution\sls\855e8a7c-ecb4-4ca3-b045-1dfa50104289\sls.cab
- %WINDIR%\softwaredistribution\sls\855e8a7c-ecb4-4ca3-b045-1dfa50104289\tmpcb31.tmp
- %WINDIR%\softwaredistribution\sls\8b24b027-1dee-babb-9a95-3517dfb9c552\sls.cab
- %WINDIR%\softwaredistribution\sls\8b24b027-1dee-babb-9a95-3517dfb9c552\tmpcfe5.tmp
- %ALLUSERSPROFILE%\microsoft\windows\onesettings\ctac.json
- %ALLUSERSPROFILE%\microsoft\windows\onesettings\sccinstallservice.json
- DNS ASK settings-win.data.microsoft.com
- ClassName: 'OleMainThreadWndClass' WindowName: ''
- '<PATH_SAMPLE>_3205.exe' -nomutate
- '<SYSTEM32>\waasmedicagent.exe' {D672D389-24E2-4F05-B79F-FB55837F4595} 2oYu5uLCZUSWk8BI.0.0.0