Aerosol Posted May 24, 2015 Report Posted May 24, 2015 The virus on VT:https://www.virustotal.com/en/file/8f35f6f780acccfb406b918db6ef01111dd2c5200a16e97f25d35f76e2532e6d/analysis/1432362743/The virus inject many process like it:but I cann't found how it autostart.When OS restarted, it start itself via explorer.exe, but I do not know how it auto started.log:2015/05/23 15:54:55 c:\windows\explorer.exe Create new process c:\users\test\appdata\roaming\mozilla\firefox\profiles\4ude5xz7.default\storage\permanent\xulstore.exe?Cmd line: "C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\4ude5xz7.default\storage\permanent\xulstore.exe"DownloadPass:infectedSource Quote