Technical Information
To ensure autorun and distribution
Modifies the following registry keys
- [<HKLM>\software\Wow6432Node\microsoft\windows nt\currentversion\windows] 'AppInit_DLLs' = '%CommonProgramFiles%\System\symsrv.dll'
- [<HKLM>\software\Wow6432Node\microsoft\windows nt\currentversion\windows] 'LoadAppInit_DLLs' = '00000001'
Modifies file system
Creates the following files
- %CommonProgramFiles%\system\symsrv.dll