Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'wmpshellwow.exe' = '%WINDIR%\wmpshellwow.exe'
- %WINDIR%\wmpshellwow.exe
- <SYSTEM32>\netsh.exe firewall add allowedprogram program="%WINDIR%\wmpshellwow.exe" name="Windows Update Service" mode=ENABLE scope=ALL profile=ALL
- <SYSTEM32>\B7420BB110B7C15335887CFEE63775BF\unrar.exe
- %WINDIR%\wmpshellwow.exe
- <SYSTEM32>\B7420BB110B7C15335887CFEE63775BF\unrar.exe
- %WINDIR%\wmpshellwow.exe