Technical Information
- [HKLM\System\CurrentControlSet\Services\win32] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\win32] 'ImagePath' = '%CommonProgramFiles%\Microsoft Shared\MSINFO\rejoice2007.exe'
- 'win32' %CommonProgramFiles%\Microsoft Shared\MSINFO\rejoice2007.exe
- %TEMP%\ixp000.tmp\aaa.exe
- %CommonProgramFiles%\microsoft shared\msinfo\rejoice2007.exe
- %CommonProgramFiles%\microsoft shared\msinfo\delet.bat
- %CommonProgramFiles%\microsoft shared\msinfo\rejoice2007.exe
- %CommonProgramFiles%\microsoft shared\msinfo\rejoice2007.exe
- %TEMP%\ixp000.tmp\aaa.exe
- %CommonProgramFiles%\microsoft shared\msinfo\rejoice2007.exe
- ClassName: 'MS_WINHELP' WindowName: ''
- '%TEMP%\ixp000.tmp\aaa.exe'
- '%CommonProgramFiles%\microsoft shared\msinfo\rejoice2007.exe'
- '%WINDIR%\syswow64\cmd.exe' /c ""%CommonProgramFiles%\Microsoft Shared\MSINFO\Delet.bat""
- '%TEMP%\ixp000.tmp\aaa.exe' ' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c ""%CommonProgramFiles%\Microsoft Shared\MSINFO\Delet.bat""' (with hidden window)