Technical Information
- %APPDATA%\microsoft\windows\start menu\programs\startup\mc.bat
- iexplore.exe process, mswsock.dll module
- iexplore.exe process, dnsapi.dll module
- iexplore.exe process, iphlpapi.dll module
- iexplore.exe process, urlmon.dll module
- iexplore.exe process, wininet.dll module
- iexplore.exe process, advapi32.dll module
- '%WINDIR%\syswow64\shutdown.exe' -r -f
- '<SYSTEM32>\logonui.exe' /flags:0x1