Technical Information
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'NVSVC32' = '%WINDIR%\system\nxsvc32.exe'
- ClassName: 'TibiaClient', WindowName: ''
- %WINDIR%\system\nxsvc32.exe
- C:\load.bat
- <Current directory>\svchost.reg
- <Current directory>\svchost.reg
- C:\load.bat
- ClassName: 'RegEdit_RegEdit' WindowName: ''
- '%WINDIR%\syswow64\cmd.exe' /c ""C:\load.bat" "
- '%WINDIR%\syswow64\regedit.exe' /s svchost.reg
- '%WINDIR%\syswow64\cmd.exe' /c ""C:\load.bat" "' (with hidden window)