Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'REGTUReminder' = '<Full path to file> -rem'
- %WINDIR%\tasks\_updates.job
- %WINDIR%\tasks\_default.job
- %APPDATA%\73640479-0bc3-433f-a602-1b94c7e963ba\backup6.bin
- %APPDATA%\73640479-0bc3-433f-a602-1b94c7e963ba\log_10-09-2019.log
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''