Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'Check Update' = '%TEMP%\{59ce3ea3-05d0-6f86-97e8-145ca860d96a}\3GeZ32y9.exe'
- '<SYSTEM32>\svchost.exe'
- '<SYSTEM32>\msiexec.exe'
- <SYSTEM32>\svchost.exe
- <SYSTEM32>\msiexec.exe
- %TEMP%\354431100
- %TEMP%\nsp2.tmp
- 'he####grijus.net':80
- http://ds.download.windowsupdate.com/
- DNS ASK he####grijus.net
- DNS ASK ds.download.windowsupdate.com