Technical Information
- [HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\AppCertDlls] 'AppSecDll' = '%LOCALAPPDATA%\Windows Server\olghzy.dll'
- %WINDIR%\explorer.exe
- iexplore.exe
- firefox.exe
- iexplore.exe
- %LOCALAPPDATA%\windows server\olghzy.dll
- from <Full path to file> to %APPDATA%\microsoft\windows\templates\memory.tmp