Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Microsoft Help' = '%APPDATA%\{admin}\driver32.exe'
- <SYSTEM32>\cmd.exe /c C:\NKDRJ.bat
- <SYSTEM32>\cmd.exe /c C:\MRNSH.bat
- C:\NKDRJ.bat
- C:\MRNSH.bat
- C:\NKDRJ.bat
- C:\MRNSH.bat
- ClassName: 'SysListView32' WindowName: ''
- ClassName: 'RegEdit_RegEdit' WindowName: ''
- ClassName: '#32770' WindowName: ''