Technical Information
- [HKLM\SYSTEM\CurrentControlSet\Control\Lsa] 'Authentication Packages' = 'msv1_0\n<Full path to file>'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'iiijkksys' = 'rundll32.exe "<Full path to file>",DllRegisterServer'
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'gedawtsys' = 'rundll32.exe "<Full path to file>",DllRegisterServer'
- '%WINDIR%\syswow64\rundll32.exe' "<Full path to file>",DllRegisterServer