Technical Information
- [<HKLM>\software\microsoft\windows\currentversion\Run] 'WinampNew' = '%APPDATA%\WinampNew\WinampNew.exe'
- Windows Security Center
- Windows Action Center
- Hides taskbar notifications
- %TEMP%\6136594b32.tmp
- %TEMP%\53695a4f64.tmp
- %TEMP%\6331793350.tmp
- %TEMP%\5a34465042.tmp
- %TEMP%\647955777a.tmp
- %APPDATA%\winampnew\winampnew.exe
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' $key='HKLM:\SOFTWARE\Policies\Microsoft\MicrosoftEdge\PhishingFilter';if((Test-Path $key) -ne $TRUE){New-Item -path $key -Force -Verbose}; New-ItemProperty -Path $key -Force -Verbose -Name 'Pre...' (with hidden window)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' $key='HKLM:\SOFTWARE\Policies\Microsoft\Windows\DataCollection';if((Test-Path $key) -ne $TRUE){New-Item -path $key -Force -Verbose}; New-ItemProperty -Path $key -Force -Verbose -Name 'AllowTele...' (with hidden window)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' $key='HKLM:\SOFTWARE\Policies\Microsoft\MicrosoftEdge\PhishingFilter';if((Test-Path $key) -ne $TRUE){New-Item -path $key -Force -Verbose}; New-ItemProperty -Path $key -Force -Verbose -Name 'Pre...
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' $key='HKLM:\SOFTWARE\Policies\Microsoft\Windows\DataCollection';if((Test-Path $key) -ne $TRUE){New-Item -path $key -Force -Verbose}; New-ItemProperty -Path $key -Force -Verbose -Name 'AllowTele...