Technical Information
- [<HKLM>\System\CurrentControlSet\Services\Microsoft Service] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\Microsoft Service] 'ImagePath' = '%WINDIR%\SysWOW64\service.exe'
- %WINDIR%\syswow64\service.exe
- %WINDIR%\syswow64\svshost.exe
- <Current directory>\skinh_el.dll
- agmkis2
- <Current directory>\skinh_el.dll
- 'ip.##totoo.com':923
- http://un##wn.net/server/FreeAccount.html
- DNS ASK un##wn.net
- DNS ASK st##.unkown.net
- DNS ASK ip.##totoo.com
- '%WINDIR%\syswow64\service.exe'
- '%WINDIR%\syswow64\svshost.exe'
- '%WINDIR%\syswow64\service.exe' ' (with hidden window)
- '%WINDIR%\syswow64\svshost.exe' ' (with hidden window)