Technical Information
- %APPDATA%\microsoft\windows\start menu\programs\startup\updater.exe
- <SYSTEM32>\runtimebroker.exe
- updater.exe process, Wldp.dll module
- updater.exe process, Amsi.dll module
- runtimebroker.exe process, Amsi.dll module
- updater.exe process, ntdll.dll module
- %TEMP%\tmpf3e6.tmp
- %TEMP%\tmpf473.tmp
- %APPDATA%\microsoft\crypto\keys\7b1e9b5bc7b1764d378db7b774e259d2_8cf7b530-613e-439b-a8c5-ccfc0e745400
- %APPDATA%\microsoft\windows\start menu\programs\startup\updater.exe
- %TEMP%\tmpf3e6.tmp
- %TEMP%\tmpf473.tmp
- '82.##.213.206':4545
- '%APPDATA%\microsoft\windows\start menu\programs\startup\updater.exe'
- '%APPDATA%\microsoft\windows\start menu\programs\startup\updater.exe' ' (with hidden window)