Technical Information
- [<HKLM>\System\CurrentControlSet\Services\asp.net] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\asp.net] 'ImagePath' = '%CommonProgramFiles%\Microsoft Shared\MSINFO\asp.net'
- 'asp.net' %CommonProgramFiles%\Microsoft Shared\MSINFO\asp.net
- %WINDIR%\syswow64\mstsc.exe
- %CommonProgramFiles%\microsoft shared\msinfo\asp.net
- C:\autorun.inf
- C:\asp.net
- D:\autorun.inf
- D:\asp.net
- %WINDIR%\syswow64\_asp.net
- %CommonProgramFiles%\microsoft shared\msinfo\redelbat.bat
- %CommonProgramFiles%\microsoft shared\msinfo\asp.net
- C:\autorun.inf
- C:\asp.net
- D:\autorun.inf
- D:\asp.net
- %WINDIR%\syswow64\_asp.net
- ClassName: 'MS_WINHELP' WindowName: ''
- '%CommonProgramFiles%\microsoft shared\msinfo\asp.net'
- '%WINDIR%\syswow64\cmd.exe' /c ""%CommonProgramFiles%\Microsoft Shared\MSINFO\ReDelBat.bat""' (with hidden window)
- '%WINDIR%\syswow64\calc.exe'
- '%WINDIR%\syswow64\mstsc.exe'
- '%WINDIR%\syswow64\cmd.exe' /c ""%CommonProgramFiles%\Microsoft Shared\MSINFO\ReDelBat.bat""