Technical Information
- \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Perflib\009
- '<SYSTEM32>\schtasks.exe' /delete /tn crconfig.exe /f' (with hidden window)
- '<SYSTEM32>\cmd.exe' /C choice /C Y /N /D Y /T 1 & Del "<Full path to file>"' (with hidden window)
- '<SYSTEM32>\wbem\wmiapsrv.exe'
- '<SYSTEM32>\schtasks.exe' /delete /tn crconfig.exe /f
- '<SYSTEM32>\cmd.exe' /C choice /C Y /N /D Y /T 1 & Del "<Full path to file>"