Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '017402f8463ac0ece654c5d863571b46' = '"%APPDATA%\winupdj.exe" ..'
- [<HKLM>\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '017402f8463ac0ece654c5d863571b46' = '"%APPDATA%\winupdj.exe" ..'
- '%WINDIR%\syswow64\netsh.exe' firewall add allowedprogram "%APPDATA%\winupdj.exe" "winupdj.exe" ENABLE
- winupdj.exe
- %APPDATA%\winupdj.exe
- DNS ASK un#####.twilightparadox.com
- '%APPDATA%\winupdj.exe'
- '%WINDIR%\syswow64\netsh.exe' firewall add allowedprogram "%APPDATA%\winupdj.exe" "winupdj.exe" ENABLE' (with hidden window)