Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Windows Services' = '%TEMP%\svchost.exe /k'
- ClassName: 'PROCMON_WINDOW_CLASS' WindowName: '(null)'
- ClassName: 'gdkWindowToplevel' WindowName: '(null)'
- %TEMP%\svchost.exe
- 'co##a.zz.mu':80
- 'localhost':1035
- co##a.zz.mu/test.txt
- DNS ASK co##a.zz.mu
- ClassName: 'TLauncher' WindowName: '(null)'
- ClassName: 'TApplication' WindowName: '(null)'
- ClassName: 'TProcCleanMainForm' WindowName: '(null)'
- ClassName: 'PCHShell Window' WindowName: '(null)'
- ClassName: 'ProcessHacker' WindowName: '(null)'
- ClassName: 'regfromapp' WindowName: '(null)'
- ClassName: '18467-41' WindowName: '(null)'
- ClassName: 'RegEdit_RegEdit' WindowName: '(null)'
- ClassName: 'PROCEXPL' WindowName: '(null)'
- ClassName: 'TCPViewClass' WindowName: '(null)'
- ClassName: 'PortmonClass' WindowName: '(null)'