2
Using autoruns from sysinternals, I found a suspect row in the tab 'VMI'
There is a Powerlog item, in the folder WMI Database Entries.
I clicked with right, and "Jump to Entry".
This opened my notepad.exe showing me the script content: so I sadly discovered it contains VERY VERY VERY BAD CODE.
I know I can simply delete the entry from inside Autoruns utility.
But I'm here to ask you: - What are WMI Database Entries - Where are them located on my disk or my registry, or whatelse?