Technical Information
- [<HKLM>\System\CurrentControlSet\Services\hkmsvcSys] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\hkmsvcSys] 'ImagePath' = '<SYSTEM32>\com\svchost.exe'
- 'hkmsvcSys' <SYSTEM32>\com\svchost.exe
- %WINDIR%\syswow64\svchost.exe
- %ALLUSERSPROFILE%\mozilla\vg9cwffabwvfxajrba.bin
- %WINDIR%\syswow64\com\svchost.exe
- %ALLUSERSPROFILE%\mozilla\vg9cwffabwvfxajrba.bin
- %WINDIR%\syswow64\com\svchost.exe
- from <Full path to file> to <Full path to file>1
- '37.##5.54.48':443
- DNS ASK pu###c-dns.us
- '%WINDIR%\syswow64\svchost.exe' -k netsvcs