Technical Information
- <SYSTEM32>\ctfmon.exe with <Full path to file>.temp
- from <Full path to file> to <Full path to file>.temp
- '<SYSTEM32>\ctfmon.exe'
- '<SYSTEM32>\cmd.exe' /c attrib +h +s +r "<SYSTEM32>\ctfmon.exe"
- '<SYSTEM32>\attrib.exe' +h +s +r "<SYSTEM32>\ctfmon.exe"