Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'CacheClear' = '"%PROGRAMDATA%\Thumbsdb.bat"'
- %PROGRAMDATA%\thumbsdb.bat
- '%WINDIR%\syswow64\cmd.exe' /c ""%PROGRAMDATA%\Thumbsdb.bat" "' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c ""%PROGRAMDATA%\Thumbsdb.bat" "