Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\Tz0FF] 'Start' = '00000000'
- [<HKLM>\SYSTEM\ControlSet001\Services\Tz0OTFE] 'Start' = '00000000'
- [<HKLM>\SYSTEM\ControlSet001\Services\NetworkAgent] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\NetworkAgent] 'ImagePath' = '<SYSTEM32>\wwtask.exe -service'
- '<SYSTEM32>\wwtask.exe' -service
- <DRIVERS>\Tz0FF.sys
- <DRIVERS>\Tz0Otfe.sys
- %WINDIR%\NetworkClient\Library\tz0input.dll
- <SYSTEM32>\Tz0FF.dll
- <SYSTEM32>\wwtask.exe
- %WINDIR%\NetworkClient\t0_debug.txt
- %WINDIR%\NetworkClient\awtask.exe
- <SYSTEM32>\wwtask.exe
- '17#.#0.21.55':80
- 17#.#0.21.55/collecti.php?tz########################################################################################################################################
- ClassName: '(null)' WindowName: 'Program Manager'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'