Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\NetworkAgent] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\NetworkAgent] 'ImagePath' = '<SYSTEM32>\wwtask.exe -service'
- [<HKLM>\SYSTEM\ControlSet001\Services\Tz0FF] 'Start' = '00000000'
- [<HKLM>\SYSTEM\ControlSet001\Services\Tz0FF] 'ImagePath' = 'system32\DRIVERS\Tz0FF.sys'
- [<HKLM>\SYSTEM\ControlSet001\Services\Tz0OTFE] 'Start' = '00000000'
- [<HKLM>\SYSTEM\ControlSet001\Services\Tz0OTFE] 'ImagePath' = 'System32\Drivers\Tz0Otfe.sys'
- %WINDIR%\NetworkClient\Cfg\core.cfg
- <SYSTEM32>\wwtask.exe
- %WINDIR%\NetworkClient\Cfg\dbsec.cfg
- %WINDIR%\NetworkClient\API\awtask.exe
- %WINDIR%\NetworkClient\Library\tz0ff32.dll
- <DRIVERS>\Tz0FF.sys
- <DRIVERS>\Tz0Otfe.sys
- %WINDIR%\NetworkClient\Library\tz0input.dll
- %WINDIR%\NetworkClient\Cfg\perf.cfg
- %WINDIR%\NetworkClient\Cfg\guard.cfg
- <SYSTEM32>\wwtask.exe
- ClassName: '' WindowName: 'Program Manager'
- '<SYSTEM32>\wwtask.exe' -service