Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'importantupdates' = '"%APPDATA%\importantupdates\importantupdates.exe" '
- %APPDATA%\microsoft\windows\start menu\programs\startup\importantupdates.vbs
- %APPDATA%\importantupdates\importantupdates.exe
- %APPDATA%\importantupdates\data.exe
- %APPDATA%\importantupdates\license.txt
- 'mi###circle.com':80
- DNS ASK mi###circle.com
- DNS ASK xm#.##nercircle.com
- '%APPDATA%\importantupdates\data.exe'
- '%APPDATA%\importantupdates\importantupdates.exe'