Technical Information
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'ifp' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'ifp' = '%WINDIR%\syswow64\ipf.exe'
- %WINDIR%\syswow64\drivers\winut.dat
- %WINDIR%\syswow64\ipf.exe
- '%WINDIR%\syswow64\ipf.exe'
- '%WINDIR%\syswow64\ipf.exe' ' (with hidden window)