Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'WinService' = '%WINDIR%\WinService\WinService.exe'
- User Account Control (UAC)
- %WINDIR%\WinService\WinSxSFS.dll
- %WINDIR%\WinService\WinSxS.dll
- %WINDIR%\WinService\WinService.exe
- 'localhost':3306