Technical Information
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'MuxgoFgags' = 'regsvr32.exe "%ALLUSERSPROFILE%\MuxgoFgags\MatuCduyf.mlh"'
- <SYSTEM32>\spoolsv.exe
- <SYSTEM32>\wudfhost.exe
- %WINDIR%\explorer.exe
- <SYSTEM32>\rundll32.exe
- <SYSTEM32>\wbem\wmiprvse.exe
- <SYSTEM32>\sppsvc.exe
- iexplore.exe
- firefox.exe
- firefox.exe process, crypt32.dll module
- firefox.exe process, advapi32.dll module
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '2500' = '00000003'
- %ALLUSERSPROFILE%\muxgofgags\matucduyf.mlh