Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '*' = '"%ALLUSERSPROFILE%\WinMngr\svchost.exe"'
- hidden files
- '%ALLUSERSPROFILE%\WinMngr\procmon.exe'
- %ALLUSERSPROFILE%\WinMngr\procmon.exe
- %ALLUSERSPROFILE%\WinMngr\procmon.exe
- from <Full path to virus> to %ALLUSERSPROFILE%\WinMngr\svchost.exe
- 'so##c4us.in':80
- so##c4us.in/l/page.php
- DNS ASK so##c4us.in
- ClassName: 'Shell_TrayWnd' WindowName: ''