Technical Information
To ensure autorun and distribution:
Creates or modifies the following files:
- %HOMEPATH%\Start Menu\Programs\Startup\Microsoft UpdatX.lnk
Modifies file system:
Creates the following files:
- %TEMP%\Server.exe
- %TEMP%\arxjsuc
- %TEMP%\aut1.tmp
Deletes the following files:
- %TEMP%\arxjsuc
- %TEMP%\aut1.tmp
Network activity:
Connects to:
- 'xy####.hopto.org':2825
UDP:
- DNS ASK xy####.hopto.org