Technical Information
- <SYSTEM32>\tasks\firefox
- C:\users\public\downloads\sfgreg.zip
- %APPDATA%\1158681\firefoxs\temp.log
- %APPDATA%\1158681\firefoxs\task.dat
- %APPDATA%\1158681\firefoxs\vmprotectsdk32.dll
- %APPDATA%\1158681\firefoxs\errhandle.dll
- %APPDATA%\1158681\firefoxs\svcproxy.dll
- %APPDATA%\1158681\firefoxs\managementagenthost.exe
- C:\users\public\desktop.log
- C:\users\public\downloads\sfgreg.zip
- http://43.##9.24.202/13977.zip
- DNS ASK 36#.####ecounterstrike.com
- ClassName: 'MS_WINHELP' WindowName: ''
- '%APPDATA%\1158681\firefoxs\managementagenthost.exe' -GetHFCWSPObj