Technical Information
- [<HKLM>\System\CurrentControlSet\Services\PSEXESVC] 'ImagePath' = '%WINDIR%\PSEXESVC.exe'
- 'PSEXESVC' %WINDIR%\PSEXESVC.exe
- %WINDIR%\syswow64\psexec64.exe
- %WINDIR%\syswow64\psexec64.exe
- <SYSTEM32>\psexec64.exe
- %WINDIR%\psexesvc.exe
- unc\orpzhjzhsu\pipe\psexesvc
- %WINDIR%\psexesvc.exe
- %WINDIR%\syswow64\psexec64.exe
- <SYSTEM32>\psexec64.exe
- from <Full path to file> to %WINDIR%\temp\ltq1191535\....\temporaryfile
- from <Full path to file> to %WINDIR%\temp\ltq1193392\....\temporaryfile
- <Full path to file>
- %WINDIR%\psexesvc.exe
- from <Full path to file> to %TEMP%\ltq1189866\....\temporaryfile
- '%WINDIR%\syswow64\psexec64.exe' -i -d -s <Full path to file>
- '%WINDIR%\psexesvc.exe'
- '%WINDIR%\syswow64\psexec64.exe' -i -d -s <Full path to file>' (with hidden window)