Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Windows Updater' = '%TEMP%\svchost.com'
- <PATH_SAMPLE>atubcopy
- %TEMP%\svchost.com
- %TEMP%\svchostatubcopy
- %TEMP%\svchost.com
- <PATH_SAMPLE>atubcopy
- %TEMP%\svchostatubcopy
- '<LOCALNET>.2.7':8888
- '%TEMP%\svchost.com'
- '%TEMP%\svchost.com' ' (with hidden window)