Technical Information
- <SYSTEM32>\tasks\googleupdatetaskmachineqc
- [<HKLM>\System\CurrentControlSet\Services\WinRing0_1_2_0] 'ImagePath' = '<SYSTEM32>\config\systemprofile\AppData\Roaming\Google\Libs\WR64.sys'
- 'WinRing0_1_2_0' <SYSTEM32>\config\systemprofile\AppData\Roaming\Google\Libs\WR64.sys
- <SYSTEM32>\conhost.exe
- DNS ASK po##.#ashvault.pro
- DNS ASK pa###bin.com
- '%ProgramFiles%\google\chrome\updater.exe'
- '%ProgramFiles%\google\chrome\updater.exe' ' (with hidden window)