Technical Information
- %WINDIR%\Tasks\RCX1.tmp
- %WINDIR%\Tasks\windhelp.dll
- %WINDIR%\Tasks\wumsvc1.cc3
- [<HKLM>\SYSTEM\ControlSet001\Services\seclogon] 'Start' = '00000002'
- '<SYSTEM32>\svchost.exe' -k netsvcs
- %WINDIR%\Tasks\windhelp.dll
- %WINDIR%\Tasks\wumsvc1.cc3
- 'localhost':1043
- 'vi#.##pfacebook.com':80
- vi#.##pfacebook.com/comment.php
- DNS ASK vi#.##pfacebook.com