Technical Information
- [<HKLM>\System\CurrentControlSet\Services\RSSSSSSSS] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\RSSSSSSSS] 'ImagePath' = '<SYSTEM32>\svchost.exe -k OOOOPPPP'
- [<HKLM>\SYSTEM\CurrentControlSet\Services\RSSSSSSSS\Parameters] 'ServiceDll' = '<Full path to file>'
- %WINDIR%\syswow64\okuxm6yh.dll
- http://www.ha##23.com/
- http://www.86#4.cn/
- http://www.xi##.net/
- DNS ASK ha##23.com
- DNS ASK 86#4.cn
- DNS ASK xi##.net
- ClassName: 'MS_WINHELP' WindowName: ''
- '%WINDIR%\syswow64\svchost.exe' -k OOOOPPPP