Technical Information
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'run' = '%APPDATA%\Microsoft\msconfig.exe'
- %APPDATA%\Microsoft\msconfig.exe
- <Full path to file>
- '<SYSTEM32>\attrib.exe' +H %APPDATA%\Microsoft\msconfig.exe
- '<SYSTEM32>\attrib.exe' +H <Full path to file>