Mission: Locate the persistence mechanism (malware autostart).
Currently viewing the primary hive file. Navigate to Software\Microsoft\Windows\CurrentVersion\Run.

ROOT
Software
Microsoft
Windows
CurrentVersion
Run
RunOnce
Path: \Software\Microsoft\Windows\CurrentVersion\Run
Name Type Data
OneDrive REG_SZ "C:\Users\Admin\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
SecurityHealth REG_EXPAND_SZ %windir%\system32\SecurityHealthSystray.exe