Technical Information
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\startup\<File name>.exe
- <Current directory>\batchscript.bat
- '%ALLUSERSPROFILE%\microsoft\windows\start menu\programs\startup\<File name>.exe' restart
- '<SYSTEM32>\cmd.exe' /C BatchScript.bat & Del BatchScript.bat' (with hidden window)
- '<SYSTEM32>\cmd.exe' /C BatchScript.bat & Del BatchScript.bat
- '<SYSTEM32>\tasklist.exe' /fi "PID eq 1672"
- '<SYSTEM32>\find.exe' ":"