Technical Information
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Windows Live' = '%TEMP%\winini.exe'
- winlogon.exe
- %TEMP%\winini.exe
- %TEMP%\winlogon.exe
- %APPDATA%\rundll32.exe
- %APPDATA%\rundll32.exe
- '%TEMP%\winini.exe'
- '%TEMP%\winlogon.exe'
- '%APPDATA%\rundll32.exe'
- '%APPDATA%\rundll32.exe' ' (with hidden window)