Technical Information
- [HKLM\System\CurrentControlSet\Services\HVIDMNG] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\HVIDMNG] 'ImagePath' = '%WINDIR%\systam32\<File name>.exe -netsvcs'
- 'HVIDMNG' %WINDIR%\systam32\<File name>.exe -netsvcs
- %WINDIR%\systam32\<File name>.exe
- 'on##.net':7064
- DNS ASK ti###bar.net
- DNS ASK sl###pdate.net
- DNS ASK on##.net
- '%WINDIR%\systam32\<File name>.exe' -netsvcs