Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'WindowsBOOT.exe' = '"%PROGRAMDATA%\Windows firewall update for microsoft.exe" ..'
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] 'WindowsBOOT.exe' = '"%PROGRAMDATA%\Windows firewall update for microsoft.exe" ..'
- %APPDATA%\microsoft\windows\start menu\programs\startup\windowsboot.exe.exe
- <LS_APPDATA>\tempserver.exe
- %PROGRAMDATA%\windows firewall update for microsoft.exe
- %PROGRAMDATA%\windows firewall update for microsoft.exe
- DNS ASK pa######scobar.duckdns.org
- '<LS_APPDATA>\tempserver.exe'
- '%PROGRAMDATA%\windows firewall update for microsoft.exe'