Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\WsysSvc] 'Start' = '00000002'
- '%ALLUSERSPROFILE%\Application Data\eSafe\eGdpSvc.exe'
- '%ALLUSERSPROFILE%\Application Data\eSafe\eGdpSvc.exe' -run
- %ALLUSERSPROFILE%\Application Data\eSafe\log\eGdpSvc.LOG
- %ALLUSERSPROFILE%\Application Data\eSafe\eGdpSvc.exe
- <SYSTEM32>\PerfStringBackup.TMP
- <SYSTEM32>\wbem\Performance\WmiApRpl.ini
- 'xa.###gcloud.com':80
- xa.###gcloud.com/v4/sof-newgdp/<Auxiliary name>X<Auxiliary name>XIDEXHardXDrive_11000000000000000001?ac#################################################################################################
- xa.###gcloud.com/v4/sof-newgdp/<Auxiliary name>X<Auxiliary name>XIDEXHardXDrive_11000000000000000001?ac##############################################################################################
- DNS ASK xa.###gcloud.com