Technical Information
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ctfmon.exe] 'Debugger' = '<SYSTEM32>\ctfmontpq.exe'
- %WINDIR%\syswow64\cs72806.dll
- %WINDIR%\syswow64\ctfmontpq.exe
- '%WINDIR%\syswow64\regsvr32.exe' /s <SYSTEM32>\cs72806.dll