If possible, you would run an antimalware scan of your choice to detect if the trojan is on other machines.
We can check the registry keys to see if the malware/trojan has an Autorun key. These keys are stored in the following path:
“HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, RunOnce, RunOnceEx”
“We can do this with the hivelist plugin of the volatility framework. Run the command, “volatility -f cridex.vmem –profile=WinXPSP2x86 hivelist”. Shown below.