Malicious Registry Run Key Added
Registry modification detected adding a new value to HKCU\Software\Microsoft\Windows\CurrentVersion\Run. The entry points to a file in %AppData%\Roaming\Microsoft\Windows named svchost32.exe, which is not a legitimate Windows system file. The file was created 3 minutes prior by a PowerShell process with encoded command line arguments.


