Technical Information
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Windows] 'AppInit_DLLs' = '<SYSTEM32>\mmmkhzkh.dll'
- %WINDIR%\syswow64\mmmkhzkh.dll
- <Current directory>\preved.bat
- '%WINDIR%\syswow64\cmd.exe' /c preved.bat' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c preved.bat