Technical Information
- [<HKLM>\software\Wow6432Node\microsoft\windows\currentversion\Policies\Explorer\Run] '4283949065' = '%ProgramFiles%\mscln.exe'
- hidden files
- Windows Firewall
- Windows Update
- Windows Security Center
- Windows Defender
- User Account Control (UAC)
- %WINDIR%\syswow64\msiexec.exe
- from <Full path to file> to %ProgramFiles%\mscln.exe
- 'update.microsoft.com':80
- http://dn####vis22.com.ua/and/gate.php
- http://dn###jashkd1.ru/and/gate.php
- DNS ASK update.microsoft.com
- DNS ASK dn###jashkd1.ru
- DNS ASK dn####vis22.com.ua
- '%WINDIR%\syswow64\msiexec.exe'