Technical Information
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '<File name>' = '"%HOMEPATH%\<File name>.exe"'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' Add-MpPreference -ExclusionPath $env:UserProfile
- %WINDIR%\microsoft.net\framework\v4.0.30319\jsc.exe
- %HOMEPATH%\<File name>.exe