Technical Information
- '%WINDIR%\syswow64\rundll32.exe' C:\Users\Public\Documents\JgWGa6P.txt,DllRegisterServer
- <SYSTEM32>\csrss.exe
- C:\users\public\documents\jgwga6p.txt
- %ProgramFiles%\UNP\Logs\UpdateNotificationPipeline.001.etl
- 'ri###iral.com':443
- DNS ASK ri###iral.com
- DNS ASK ar#.msn.com
- DNS ASK im##########-rt-microsoft-com.akamaized.net
- ClassName: 'OleMainThreadWndClass' WindowName: ''
- '<SYSTEM32>\devicecensus.exe' UserCxt
- '<SYSTEM32>\svchost.exe' -k netsvcs -p