Technical Information
- [HKLM\SYSTEM\ControlSet001\services\fM4mEweL] 'Start' = '00000000'
- [HKLM\SYSTEM\ControlSet001\services\fM4mEweL] 'ImagePath' = 'system32\drivers\345rstuv.sys'
- [HKLM\SYSTEM\ControlSet002\services\fM4mEweL] 'Start' = '00000000'
- [HKLM\SYSTEM\ControlSet002\services\fM4mEweL] 'ImagePath' = 'system32\drivers\345rstuv.sys'
- <SYSTEM32>\lsass.exe
- <SYSTEM32>\svchost.exe
- <DRIVERS>\345rstuv.sys
- 'pr#.##ocools.com':12309
- DNS ASK ba##u.com
- DNS ASK pr#.##ocools.com