Technical Information
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Active Setup\Installed Components\{532D34A6-6CB8-4c25-9574-A86ECE3A7046}] 'stubpath' = 'rundll32.exe C:\Users\Public\Pictures\cserver.dll,FirstRun'
- C:\users\public\pictures\cserver.dll
- '<LOCALNET>.1.180':8088
- '%WINDIR%\syswow64\rundll32.exe' C:\Users\Public\Pictures\cserver.dll,FirstRun
- '%WINDIR%\syswow64\rundll32.exe' C:\Users\Public\Pictures\cserver.dll,MainRun