Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\winwork] 'Start' = '00000002'
- <DRIVERS>\beep.sys
- <SYSTEM32>\dllcache\beep.sys with <SYSTEM32>\dllcache\beep.sys.new
- %WINDIR%\win32.dll
- <SYSTEM32>\svchost.exe 46300
- ClassName: 'OLLYDBG' WindowName: ''
- ClassName: 'FileMonClass' WindowName: ''
- <SYSTEM32>\dllcache\beep.sys.new
- %TEMP%\10707877.tmp
- %WINDIR%\win32.dll
- '46###.rhelper.com':3000
- DNS ASK 46###.rhelper.com
- ClassName: '18467-41' WindowName: ''