Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\NetmanSys] 'ImagePath' = '%ALLUSERSPROFILE%\Application Data\Mozilla\svchost.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\NetmanSys] 'Start' = '00000002'
- '<SYSTEM32>\svchost.exe' -k netsvcs
- <SYSTEM32>\svchost.exe
- %ALLUSERSPROFILE%\Application Data\Mozilla\svchost.exe
- %ALLUSERSPROFILE%\Application Data\Mozilla\UV9FXlFbb1NfWVQPBg.bin
- %ALLUSERSPROFILE%\Application Data\Mozilla\svchost.exe
- %ALLUSERSPROFILE%\Application Data\Mozilla\UV9FXlFbb1NfWVQPBg.bin
- '19#.#46.180.43':80
- '17#.#01.223.98':443
- http://19#.#46.180.43/xJOT/jsQCuSp/sUnk/7VTyog/GbxAoZu.mlJhrFvTFC4Q.IRa8NR016W94KCMJgjXcmD1evhbf3WBlWK-qsXe7bEcJ1qNVLfwZlg9uNa47wFGrCEC8.php
- http://19#.#46.180.43/yN/vUBdWXYugodWyTY2/HN0F.r70bJzdSs-GDx15AmNCyPSnSd1FfJVwdhQg4jsG.cgi?s=##################################################