Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\videos2] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\videos2] 'ImagePath' = '%CommonProgramFiles%\Microsoft\services.exe'
- '%CommonProgramFiles%\Microsoft\services.exe' /install /silent
- '%CommonProgramFiles%\Microsoft\services.exe' (downloaded from the Internet)
- <Current directory>\services7.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\services7[1].exe
- from <Current directory>\services7.exe to %CommonProgramFiles%\Microsoft\services.exe
- 'wm###.hut2.ru':80
- wm###.hut2.ru/services7.exe
- DNS ASK wm###.hut2.ru
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: '' WindowName: '(null)'