Technical Information
- [HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] 'sysctl.exe' = '<SYSTEM32>\sysctl.exe'
- [HKLM\Software\Classes\exefile\shell\open\command] '' = '%WINDIR%\SysWow64\realex.exe "%1" %*'
- %WINDIR%\syswow64\sysctl.exe
- %WINDIR%\syswow64\realex.exe
- '%WINDIR%\syswow64\sysctl.exe'
- '%WINDIR%\syswow64\sysctl.exe' ' (with hidden window)