Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'services' = '%WINDIR%\services.exe'
- Windows Security Center
- Windows Security Center
- '<SYSTEM32>\netsh.exe' firewall set opmode DISABLE
- '%WINDIR%\services.exe'
- '<SYSTEM32>\cmd.exe' /c "file.bat"
- %WINDIR%\services.exe
- %WINDIR%\file.bat
- %WINDIR%\services.exe