Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Microsoft® Windows® Operating System' = '%APPDATA%\Windows\wuauserv.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Microsoft® Windows® Operating System' = '\Windows\wuauserv.exe'
- '<SYSTEM32>\wbem\wmiadap.exe' /R /T
- %APPDATA%\Imminent\Logs\15-02-2015
- %APPDATA%\Imminent\Path.dat
- %WINDIR%\wuauserv.exe
- %APPDATA%\Windows\wuauserv.exe
- <Full path to virus>
- <SYSTEM32>\wbem\Performance\WmiApRpl.ini
- 'a3##########.#eploy.static.akamaitechnologies.info':92
- DNS ASK a3##########.#eploy.static.akamaitechnologies.info
- ClassName: 'Indicator' WindowName: ''