Technical Information
- [HKLM\SYSTEM\CurrentControlSet\Services\DiagTrack] 'Start' = '00000002'
- [HKLM\SYSTEM\CurrentControlSet\Services\DiagTrack] 'ImagePath' = '%ALLUSERSPROFILE%\Microsoft\Diagnosis\ETLLogs\AutoLogger\diagtrack.exe'
- 'DiagTrack' %ALLUSERSPROFILE%\Microsoft\Diagnosis\ETLLogs\AutoLogger\diagtrack.exe
- %ALLUSERSPROFILE%\microsoft\diagnosis\etllogs\autologger\diagtrack.exe
- nul
- '1.#.1.1':443
- '1.#.1.1':443
- '15#.#01.1.91':443
- '%ALLUSERSPROFILE%\microsoft\diagnosis\etllogs\autologger\diagtrack.exe'
- '<SYSTEM32>\cmd.exe' /c "cmd.exe /c timeout /t 3 /nobreak >nul && del /f /q \"<Full path to file>\" >nul 2>&1"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -WindowStyle Hidden -Command "Start-Sleep -Seconds 4; Remove-Item -Path '<Full path to file>' -Force -ErrorAction SilentlyContinue"
- '<SYSTEM32>\cmd.exe' /c timeout /t 3 /nobreak
- '<SYSTEM32>\timeout.exe' /t 3 /nobreak