Technical Information
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'WindowsUpdateService' = '%APPDATA%\WindowsUpdateService\svchost.exe'
- %APPDATA%\windowsupdateservice\svchost.exe
- nul
- 'ap#.#pify.org':443
- 'in##mnia.ru':80
- 'ap#.#pify.org':443
- DNS ASK ap#.#pify.org
- DNS ASK in##mnia.ru
- '%APPDATA%\windowsupdateservice\svchost.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -Command "(Get-CimInstance -Namespace root/SecurityCenter2 -ClassName AntivirusProduct).displayName -join ', '"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -Command "(Get-CimInstance -Namespace root/SecurityCenter2 -ClassName AntivirusProduct).displayName -join ', '"' (with hidden window)
- '%APPDATA%\windowsupdateservice\svchost.exe' ' (with hidden window)