Technical Information
- [<HKLM>\SYSTEM\ControlSet001\services\syshost32] 'Start' = '00000002'
- '%WINDIR%\Installer\{B5FFA751-2DC1-C6E3-7DD0-37333EB79DD1}\syshost.exe' /service
- '<SYSTEM32>\netsh.exe' advfirewall firewall set rule name="Core Networking - System IP Core" dir=in new action=allow enable=yes profile=any
- %WINDIR%\Temp\95caeab8-8b62-6126-1b32-38c3f7f8105e.tmp
- %WINDIR%\Installer\{B5FFA751-2DC1-C6E3-7DD0-37333EB79DD1}\syshost.exe
- from <Full path to virus> to %TEMP%\2c502d6e.tmp
- DNS ASK dn#.##ftncsi.com
- DNS ASK microsoft.com
- ClassName: 'Shell_TrayWnd' WindowName: ''