Technical Information
- [HKLM\SYSTEM\CurrentControlSet\Services\Group Backup WinHTTP Counter Drive Parental] 'Start' = '00000002'
- [HKLM\SYSTEM\CurrentControlSet\Services\Group Backup WinHTTP Counter Drive Parental] 'ImagePath' = 'C:\fvmgrsdszac\hphgneuj.exe'
- 'Group Backup WinHTTP Counter Drive Parental' C:\fvmgrsdszac\hphgneuj.exe
- %WINDIR%\fvmgrsdszac\hxepbl1p
- C:\fvmgrsdszac\hxepbl1p
- C:\fvmgrsdszac\vyvilkr7bbocebxofql.exe
- C:\fvmgrsdszac\hphgneuj.exe
- C:\fvmgrsdszac\aieksrpf.exe
- C:\fvmgrsdszac\hphgneuj.exe
- C:\fvmgrsdszac\aieksrpf.exe
- %WINDIR%\fvmgrsdszac\hxepbl1p
- C:\fvmgrsdszac\vyvilkr7bbocebxofql.exe
- %WINDIR%\fvmgrsdszac\hxepbl1p
- DNS ASK fi#####.###tings.services.mozilla.com
- DNS ASK ri####problem.net
- 'C:\fvmgrsdszac\vyvilkr7bbocebxofql.exe'
- 'C:\fvmgrsdszac\hphgneuj.exe'
- 'C:\fvmgrsdszac\aieksrpf.exe' "c:\fvmgrsdszac\hphgneuj.exe"