Technical Information
- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '<File name>' = '%HOMEPATH%\<File name>.exe'
- <SYSTEM32>\svchost.exe
- <SYSTEM32>\notepad.exe
- %WINDIR%\microsoft.net\framework\v4.0.30319\aspnet_wp.exe
- <SYSTEM32>\securityhealthsystray.exe
- %WINDIR%\syswow64\findstr.exe
- %HOMEPATH%\<File name>.exe
- '%WINDIR%\microsoft.net\framework\v4.0.30319\aspnet_wp.exe'
- '%WINDIR%\syswow64\findstr.exe'