Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Sync' = '%ALLUSERSPROFILE%\SyncFiles\rekeywiz.exe'
- '%WINDIR%\syswow64\schtasks.exe' /create /tn "UpdateService" /sc once /tr "%ALLUSERSPROFILE%\SyncFiles\rekeywiz.exe" /st 15:53
- %TEMP%\1.a
- %ALLUSERSPROFILE%\syncfiles\rekeywiz.exe
- %ALLUSERSPROFILE%\syncfiles\duser.dll
- %ALLUSERSPROFILE%\syncfiles\iknb8zm.tmp
- %ALLUSERSPROFILE%\syncfiles\rekeywiz.exe.config
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding