Technical Information
- [HKLM\SOFTWARE\Wow6432Node\MICROSOFT\WINDOWS\CURRENTVERSION\RUN] '' = '<SYSTEM32>\config\winupdman.exe'
- %TEMP%\aiw735451.bmp
- %TEMP%\aaiw735452.bmp
- %TEMP%\aiw735466.bmp
- %WINDIR%\syswow64\msinet.ocx
- %WINDIR%\syswow64\mswinsck.ocx
- %WINDIR%\syswow64\winupdman.exe
- %APPDATA%\Microsoft\windows\Start Menu\programs\application name\application name uninstaller.lnk
- %WINDIR%\syswow64\config\winupdman.exe
- %TEMP%\aiw735451.bmp
- %TEMP%\aaiw735452.bmp
- %TEMP%\aiw735466.bmp
- 'my#p.dk':80
- 'ou#.#irgilio.it':25
- http://www.my#p.dk/
- '34.##9.100.209':443
- 'ou#.#irgilio.it':25
- DNS ASK my#p.dk
- DNS ASK ou#.#irgilio.it
- '%WINDIR%\syswow64\winupdman.exe'
- '<SYSTEM32>\rundll32.exe' <SYSTEM32>\FirewallControlPanel.dll,ShowNotificationDialog /configure /ETOnly 0 /OnProfiles 6 /OtherAllowed 0 /OtherBlocked 0 /OtherEdgeAllowed 0 /NewBlocked 4 "%WINDIR%\syswow64\winupdman.exe"