Technical Information
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = 'explorer.exe "<SYSTEM32>\wmiservice.exe"'
- %WINDIR%\syswow64\wmiservice.exe
- <Current directory>\cmd.bat
- '%WINDIR%\syswow64\cmd.exe' /c cmd.bat' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c cmd.bat
- '%WINDIR%\syswow64\ping.exe' localhost -n 2