Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\wmcserv] 'Start' = '00000002'
- '<SYSTEM32>\wmcserv.exe' -d "%TEMP%\norton.exe"
- '<SYSTEM32>\wmcserv.exe' -v
- '%TEMP%\12TO13.EXE'
- '%TEMP%\norton.exe'
- <SYSTEM32>\lsass.exe
- <SYSTEM32>\wmcserv.exe
- %TEMP%\norton.exe
- %TEMP%\12TO13.EXE
- <SYSTEM32>\wmcserv.exe
- %TEMP%\norton.exe
- 'ww#####rosoft.9966.org':80
- DNS ASK ww#####rosoft.9966.org
- ClassName: 'Shell_TrayWnd' WindowName: ''