Technical Information
- [HKLM\System\CurrentControlSet\Services\zfzjmw] 'Start' = '00000000'
- [HKLM\System\CurrentControlSet\Services\zfzjmw] 'ImagePath' = 'system32\drivers\twrkj.sys'
- 'zfzjmw' <DRIVERS>\twrkj.sys
- %APPDATA%\microsoft\internet explorer\quick launch\æô¶¯ internet explorer ä¯à à æ÷.lnk
- %WINDIR%\syswow64\lmmb.dll
- %WINDIR%\syswow64\drivers\twrkj.sys
- '%WINDIR%\syswow64\rundll32.exe' <SYSTEM32>\Lmmb.dll,DllRegisterServer
- '%WINDIR%\syswow64\rundll32.exe' <SYSTEM32>\Lmmb.dll,DllUnregisterServer
- '%WINDIR%\syswow64\rundll32.exe' <SYSTEM32>\Lmmb.dll,DllRegisterServer' (with hidden window)
- '%WINDIR%\syswow64\rundll32.exe' <SYSTEM32>\Lmmb.dll,DllUnregisterServer' (with hidden window)