Creates this registry value:
HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell
points to the malicious that was run.
Creates a bad value under this key:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Look for a value similar to: "S112106111" which points to the malicious file that was run.
Main objective is to delete the one malicious file you ran. For example I ran a
↧