Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\Supdater] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '%PROGRAM_FILES%\Supdater\Supdater.exe' = '%PROGRAM_FILES%\Supdater\Supdater.exe:*:Enabled:Supdater'
- '%PROGRAM_FILES%\Supdater\Supdater.exe'
- '%PROGRAM_FILES%\Supdater\Supdater.exe' --install
- '<SYSTEM32>\wbem\wmiadap.exe' /R /T
- '<SYSTEM32>\sc.exe' failure "Supdater" reset= 2 actions= restart/10000
- '<SYSTEM32>\netsh.exe' firewall add allowedprogram "%PROGRAM_FILES%\Supdater\Supdater.exe" Supdater ENABLE
- %PROGRAM_FILES%\Supdater\Supdater.InstallLog
- %PROGRAM_FILES%\Supdater\Supdater.InstallState
- %PROGRAM_FILES%\Supdater\Supdater.exe
- %PROGRAM_FILES%\Supdater\Uninstall.exe
- %PROGRAM_FILES%\Supdater\Supdater.InstallState
- <SYSTEM32>\PerfStringBackup.TMP
- <SYSTEM32>\wbem\Performance\WmiApRpl.ini
- %PROGRAM_FILES%\Supdater\Supdater.InstallLog
- 'su###ter.com':443
- 'wp#d':80
- wp#d/wpad.dat
- DNS ASK su###ter.com
- DNS ASK wp#d