Technical Information
- %APPDATA%\Microsoft\windows\Start Menu\programs\startup\638e7ab56.lnk
- %ProgramFiles%\65ba7e836.cpp
- ClassName: 'BEH2l' WindowName: ''
- '%WINDIR%\syswow64\rundll32.exe' <Full path to file>,work' (with hidden window)
- '%WINDIR%\syswow64\rundll32.exe' <Full path to file>,work