Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\.Net CLR] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\.Net CLR] 'ImagePath' = '<SYSTEM32>\svchost.exe -k netsvcs'
- [<HKLM>\SYSTEM\ControlSet001\Services\.Net CLR\Parameters] 'ServiceDll' = '<SYSTEM32>\Server.dll'
- %TEMP%\128187_res.tmp
- <SYSTEM32>\Server.dll
- <Full path to file>
- from %TEMP%\128187_res.tmp to <SYSTEM32>\Server.dll
- 'localhost':1990
- '<SYSTEM32>\svchost.exe' -k netsvcs