Technical Information
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'WindowsGuard' = '%APPDATA%\WindowsUpdateGuard\hidden.exe'
- %APPDATA%\windowsupdateguard\hidden.exe
- '<SYSTEM32>\ipconfig.exe' /flushdns
- '<SYSTEM32>\ipconfig.exe' /flushdns' (with hidden window)