Technical Information
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'WindowsUpdate' = '<Full path to file>'
- <Drive name for removable media>:\update.exe
- <Drive name for removable media>:\autorun.inf
- %HOMEPATH%\desktop\february_catalogue__2015.doc
- %HOMEPATH%\desktop\cveuropeo.doc
- %HOMEPATH%\desktop\uep_form_786_bulletin_1726i602.doc
- %HOMEPATH%\desktop\hadac_newsletter_july_2010_final.docx
- %HOMEPATH%\desktop\weeklysheet1215.doc
- D:\update.exe
- D:\autorun.inf
- %HOMEPATH%\desktop\february_catalogue__2015..21yenbai
- %HOMEPATH%\desktop\cveuropeo..21yenbai
- %HOMEPATH%\desktop\hadac_newsletter_july_2010_final..21yenbai
- %HOMEPATH%\desktop\uep_form_786_bulletin_1726i602..21yenbai
- C:\users\public\cache.tmp
- %HOMEPATH%\desktop\weeklysheet1215..21yenbai
- %HOMEPATH%\desktop\cveuropeo..21yenbai
- %HOMEPATH%\desktop\hadac_newsletter_july_2010_final..21yenbai
- %HOMEPATH%\desktop\weeklysheet1215..21yenbai
- %HOMEPATH%\desktop\february_catalogue__2015..21yenbai
- %HOMEPATH%\desktop\uep_form_786_bulletin_1726i602..21yenbai
- 'ap#.##legram.org':443
- 'ap#.##legram.org':443
- DNS ASK ap#.##legram.org