Technical Information
- [HKLM\SYSTEM\CurrentControlSet\Services\syshost32] 'Start' = '00000002'
- [HKLM\SYSTEM\CurrentControlSet\Services\syshost32] 'ImagePath' = '"%WINDIR%\Installer\{313F7368-29BA-FCEA-D514-E8C2B5048A0E}\syshost.exe" /service'
- 'syshost32' %WINDIR%\Installer\{313F7368-29BA-FCEA-D514-E8C2B5048A0E}\syshost.exe" /servic
- %WINDIR%\installer\{313f7368-29ba-fcea-d514-e8c2b5048a0e}\syshost.exe
- from <Full path to file> to %TEMP%\dfe29b50.tmp
- 'mo#####.map.fastly.net':443
- 'co##############e-chains.prod.autograph.services.mozaws.net':443
- DNS ASK mo#####.map.fastly.net
- DNS ASK co##############e-chains.prod.autograph.services.mozaws.net
- '%WINDIR%\installer\{313f7368-29ba-fcea-d514-e8c2b5048a0e}\syshost.exe' /service
- '%WINDIR%\syswow64\cmd.exe' /C del /Q /F "%TEMP%\dfe29b50.tmp"
- '%WINDIR%\syswow64\cmd.exe' /C del /Q /F "%TEMP%\dfe29b50.tmp"' (with hidden window)