Technical Information
- [HKLM\SYSTEM\CurrentControlSet\Services\{AC4CA038-CE29-4941-BD0F-B467D19295DE}] 'ImagePath' = '%WINDIR%\Temp\{2B1047CC-6C08-4813-8C96-E3AD099890DB}.sys'
- '{AC4CA038-CE29-4941-BD0F-B467D19295DE}' %WINDIR%\Temp\{2B1047CC-6C08-4813-8C96-E3AD099890DB}.sys
- firefox.exe process, advapi32.dll module
- firefox.exe process, mswsock.dll module
- firefox.exe process, iphlpapi.dll module
- firefox.exe process, dnsapi.dll module
- firefox.exe process, wininet.dll module
- iexplore.exe process, dnsapi.dll module
- iexplore.exe process, mswsock.dll module
- firefox.exe process, winhttp.dll module
- iexplore.exe process, mshtml.dll module
- iexplore.exe process, wininet.dll module
- iexplore.exe process, secur32.dll module
- firefox.exe process, crypt32.dll module
- iexplore.exe process, iphlpapi.dll module
- iexplore.exe process, crypt32.dll module
- iexplore.exe process, cryptnet.dll module
- iexplore.exe process, advapi32.dll module
- firefox.exe process, urlmon.dll module
- iexplore.exe process, urlmon.dll module
- iexplore.exe process, winhttp.dll module
- <SYSTEM32>\wow64log.dll
- %WINDIR%\temp\{2b1047cc-6c08-4813-8c96-e3ad099890db}.sys
- <SYSTEM32>\wow64log.dll
- %WINDIR%\temp\{2b1047cc-6c08-4813-8c96-e3ad099890db}.sys