Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Update' = '%HOMEPATH%\Desktop\filename.exe'
- [<HKLM>\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'Update' = '%HOMEPATH%\Desktop\filename.exe'
- Command Prompt (CMD)
- User Account Control (UAC)
- filename.exe
- %HOMEPATH%\desktop\filename.exe
- %TEMP%\iaf2gokbk2.ini
- '%HOMEPATH%\desktop\filename.exe'
- '%HOMEPATH%\desktop\filename.exe' /scomma "%TEMP%\iAF2Gokbk2.ini"