Technical Information
- [<HKLM>\System\CurrentControlSet\Services\Windows Debug System Management Interface] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\Windows Debug System Management Interface] 'ImagePath' = '<Full path to file>'
- 'Windows Debug System Management Interface' <Full path to file>
- DNS ASK ka####nscript.com
- '%WINDIR%\syswow64\net.exe' start "Windows Debug System Management Interface"
- '%WINDIR%\syswow64\net1.exe' start "Windows Debug System Management Interface"