JaySon 0 Posted September 26, 2022 Hi! I just uploaded the patch to virustotal.com and saw that the patch contacts different domains and IP-addresses. Does anyone know why that is the case? Share this post Link to post
Plok 323 Posted September 27, 2022 I ran a WHOIS of those IPs, I strongly doubt it has anything to do with the patcher itself, but rather the Windows sandbox they use. arc.msn.com is called even on the first run of a clean Windows OS. Share this post Link to post