Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'Check Update' = '%TEMP%\{129adf75-cc85-02aa-828a-f39752444ce2}\603817j1.exe'
- '<SYSTEM32>\svchost.exe'
- '<SYSTEM32>\msiexec.exe'
- <SYSTEM32>\svchost.exe
- <SYSTEM32>\msiexec.exe
- %TEMP%\{129adf75-cc85-02aa-828a-f39752444ce2}\603817j1.exe
- 'fe###stats.net':80
- http://ds.download.windowsupdate.com/
- DNS ASK fe###stats.net
- DNS ASK ds.download.windowsupdate.com