Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '5b7cdf1e3cd90253117a952652c16231' = '"%TEMP%\GoogleCrashHandler.exe" ..'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '5b7cdf1e3cd90253117a952652c16231' = '"%TEMP%\GoogleCrashHandler.exe" ..'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '%TEMP%\GoogleCrashHandler.exe' = '%TEMP%\GoogleCrashHandler.exe:*:Enab...
- '%TEMP%\GoogleCrashHandler.exe'
- '%TEMP%\Dumpper.exe'
- '%TEMP%\Extensibility.exe'
- '<SYSTEM32>\netsh.exe' firewall add allowedprogram "%TEMP%\GoogleCrashHandler.exe" "GoogleCrashHandler.exe" ENABLE
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 336
- %TEMP%\1DC9F.dmp
- %TEMP%\GoogleCrashHandler.exe
- %TEMP%\dw.log
- %TEMP%\Extensibility.exe
- %TEMP%\Dumpper.exe
- 'ad###e.ddns.net':5552
- DNS ASK ad###e.ddns.net
- ClassName: 'Shell_TrayWnd' WindowName: ''