Technical Information
- [HKLM\System\CurrentControlSet\Services\khubljkmz] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\khubljkmz] 'ImagePath' = '<SYSTEM32>\attend.exe khubljkmz'
- 'khubljkmz' <SYSTEM32>\attend.exe khubljkmz
- <SYSTEM32>\attend.exe
- from <Full path to file> to <SYSTEM32>\wostmp\_218558540_2107919432
- '<SYSTEM32>\attend.exe' khubljkmz