Technical Information
- [<HKLM>\System\CurrentControlSet\Services\Poli0yAgent] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\Poli0yAgent] 'ImagePath' = '<SYSTEM32>\windb -k'
- 'Poli0yAgent' <SYSTEM32>\windb -k
- %WINDIR%\syswow64\windb -k
- %WINDIR%\syswow64\windb -k
- ClassName: 'MS_WINHELP' WindowName: ''
- '%WINDIR%\syswow64\windb -k'
- '%WINDIR%\syswow64\cmd.exe' /c del "<Full path to file>"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c del "<Full path to file>"