General Info

https://www.bleepingcomputer.com/tutorials/how-malware-hides-as-a-service/
https://www.trendmicro.com/vinfo/us/threat-encyclopedia/malware/troj_dloadr.smo
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services
$data += [PSObject] @{Path='HKLM:\System\CurrentControlSet\Services\*\'; Entries='ImagePath'}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices