Technical Information
- [HKLM\System\CurrentControlSet\Services\CreateSvcRpc_795417] 'ImagePath' = 'cmd /c start C://XXEmulator.exe'
- 'CreateSvcRpc_795417' cmd /c start C://XXEmulator.exe
- <SYSTEM32>\cmd.exe
- C:\selfstartuptask.ps1
- C:\xxemulator.exe
- '10#.#2.76.102':14992
- '10#.#2.76.102':14992
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy Bypass -File "C:\SelfStartupTask.ps1"
- 'C:\xxemulator.exe'
- '<SYSTEM32>\cmd.exe' /c start C://XXEmulator.exe
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy Bypass -File "C:\SelfStartupTask.ps1"' (with hidden window)