Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '459337a78fa55cca4aecb64eee5c57ae' = '"%TEMP%\Windows Update.exe" ..'
- [<HKLM>\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '459337a78fa55cca4aecb64eee5c57ae' = '"%TEMP%\Windows Update.exe" ..'
- '%WINDIR%\syswow64\netsh.exe' firewall add allowedprogram "%TEMP%\Windows Update.exe" "Windows Update.exe" ENABLE
- %TEMP%\windows update.exe
- 'b2#.#dns.net':1177
- DNS ASK b2#.#dns.net
- '%TEMP%\windows update.exe'
- '%WINDIR%\syswow64\netsh.exe' firewall add allowedprogram "%TEMP%\Windows Update.exe" "Windows Update.exe" ENABLE' (with hidden window)