Technical Information
- [HKLM\software\Wow6432Node\microsoft\windows\currentversion\Policies\Explorer\Run] '744529641' = '%ProgramFiles%\mssgsz.exe'
- hidden files
- Windows Firewall
- Windows Update
- Windows Security Center
- Windows Defender
- User Account Control (UAC)
- %WINDIR%\syswow64\msiexec.exe
- iexplore.exe
- %ProgramFiles%\mssgsz.exe
- from <Full path to file> to %ProgramFiles%\mssgsz.exe
- 'update.microsoft.com':80
- DNS ASK update.microsoft.com
- DNS ASK pl##oy.ru
- DNS ASK pl##oy1.ru
- DNS ASK pl##oy17.ru
- DNS ASK pl###y170.ru
- DNS ASK pl###y1700.ru
- 'localhost':56233
- 'localhost':56520
- '%WINDIR%\syswow64\msiexec.exe'