Technical Information
- %APPDATA%\microsoft\windows\start menu\programs\startup\svchost_ht.exe
- C:\$recycle.bin\s-1-5-21-3691498038-2086406363-2140527554-1000\desktop.ini.ht_encrypted
- D:\$recycle.bin\s-1-5-21-3691498038-2086406363-2140527554-1000\desktop.ini.ht_encrypted
- C:\$recycle.bin\s-1-5-21-3691498038-2086406363-2140527554-1000\desktop.ini
- D:\$recycle.bin\s-1-5-21-3691498038-2086406363-2140527554-1000\desktop.ini