Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'bugfixupdater' = '%APPDATA%\BugFixSoftware\<File name>.exe'
- %APPDATA%\BugFixSoftware\<File name>.exe
- %HOMEPATH%\Local Settings\Tempreplace.txt
- %HOMEPATH%\Local Settings\Tempreplace.cmd
- from %HOMEPATH%\Local Settings\Tempreplace.txt to %HOMEPATH%\Local Settings\Tempreplace.cmd
- 'dr##box.com':443
- DNS ASK www.google.com
- DNS ASK www.dr##box.com
- '%APPDATA%\BugFixSoftware\<File name>.exe'
- '<SYSTEM32>\cmd.exe' /c %HOMEPATH%\Local Settings\Tempreplace.cmd