Technical Information
- [HKLM\System\CurrentControlSet\Services\Windows Aues] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\Windows Aues] 'ImagePath' = '%WINDIR%\Windows Aues'
- 'Windows Aues' %WINDIR%\Windows Aues
- %WINDIR%\windows aues
- %WINDIR%\delete.bat
- %WINDIR%\windows aues
- DNS ASK cc####t.vicp.net
- '%WINDIR%\windows aues'
- '%WINDIR%\syswow64\cmd.exe' /c %WINDIR%\Delete.bat
- '%WINDIR%\syswow64\cmd.exe' /c %WINDIR%\Delete.bat' (with hidden window)