Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'DriverStartup' = '"%APPDATA%\wininit.exe" ..'
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] 'DriverStartup' = '"%APPDATA%\wininit.exe" ..'
- %APPDATA%\microsoft\windows\start menu\programs\startup\chromeupdate.exe
- <SYSTEM32>\tasks\server
- %APPDATA%\wininit.exe
- %TEMP%\server.exe
- %APPDATA%\wininit.exe
- '%APPDATA%\wininit.exe'
- '<SYSTEM32>\schtasks.exe' /create /sc minute /mo 1 /tn Server /tr <LS_APPDATA>\Temp/Server.exe' (with hidden window)
- '<SYSTEM32>\schtasks.exe' /create /sc minute /mo 1 /tn Server /tr <LS_APPDATA>\Temp/Server.exe
- '<SYSTEM32>\taskeng.exe' {88000B79-4D05-4B9C-888A-09BF425D2E3B} S-1-5-21-2922372159-162323534-3872807762-1001:syyqxcuesk\user:Interactive:[1]