Technical Information
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Windows Update' = '%APPDATA%\Windows Update.exe'
- %APPDATA%\microsoft\windows\start menu\programs\startup\windows update.exe
- %APPDATA%\<File name>.exe
- %LOCALAPPDATA%\microsoft\clr_v4.0\usagelogs\<File name>.exe.log
- %APPDATA%\windows update.exe
- %LOCALAPPDATA%\microsoft\clr_v4.0\usagelogs\windows update.exe.log
- '10.##0.11.169':1111
- '%APPDATA%\<File name>.exe'
- '%APPDATA%\microsoft\windows\start menu\programs\startup\windows update.exe'
- '%APPDATA%\windows update.exe'