Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run] 'svchost' = '"%WINDIR%\wuauctl.exe"'
- hidden files
- %WINDIR%\wuauctl.exe
- %TEMP%\~DFA0E1.tmp
- <SYSTEM32>\MSWINSCK.OCX
- %WINDIR%\wuauctl.exe
- %WINDIR%\wuauctl.exe
- 'localhost':1048
- '74.##5.232.51':443
- 'any':892
- 'any':890
- 'any':891
- DNS ASK si###.google.com