Technical Information
- <SYSTEM32>\tasks\tmp6f84.tmp
- <SYSTEM32>\tasks\tmp57fe.tmp
- %TEMP%\icbwhxfw.exe
- %ProgramFiles(x86)%\gum2d47.tmp\goopdateres_pt-pt.dll
- %ProgramFiles(x86)%\gum2d47.tmp\goopdateres_pt-br.dll
- %ProgramFiles(x86)%\gum2d47.tmp\goopdateres_pl.dll
- %ProgramFiles(x86)%\gum2d47.tmp\goopdateres_no.dll
- %ProgramFiles(x86)%\gum2d47.tmp\goopdateres_nl.dll
- %ProgramFiles(x86)%\gum2d47.tmp\goopdateres_ms.dll
- %ProgramFiles(x86)%\gum2d47.tmp\goopdateres_mr.dll
- %ProgramFiles(x86)%\gum2d47.tmp\goopdateres_ro.dll
- %ProgramFiles(x86)%\gum2d47.tmp\goopdateres_ml.dll
- %ProgramFiles(x86)%\gum2d47.tmp\goopdateres_lt.dll
- %ProgramFiles(x86)%\gum2d47.tmp\goopdateres_ko.dll
- %ProgramFiles(x86)%\gum2d47.tmp\goopdateres_kn.dll
- %ProgramFiles(x86)%\gum2d47.tmp\goopdateres_ja.dll
- %ProgramFiles(x86)%\gum2d47.tmp\goopdateres_iw.dll
- %ProgramFiles(x86)%\gum2d47.tmp\goopdateres_it.dll
- %ProgramFiles(x86)%\gum2d47.tmp\goopdateres_is.dll
- %ProgramFiles(x86)%\gum2d47.tmp\goopdateres_lv.dll
- %ProgramFiles(x86)%\gum2d47.tmp\goopdateres_uk.dll
- %TEMP%\{5cdced54-dc86-4705-85e8-5e84e165148f}-100.0.4896.127_chrome_installer.exe
- %ProgramFiles(x86)%\gum2d47.tmp\goopdateres_sl.dll
- %TEMP%\w.exe
- %LOCALAPPDATA%\servicehub\tmp6f84.tmp.exe
- %LOCALAPPDATA%\servicehub\tmp57fe.tmp.exe
- %ProgramFiles(x86)%\gum2d47.tmp\googleupdatesetup.exe
- %ProgramFiles(x86)%\gum2d47.tmp\goopdateres_zh-tw.dll
- %ProgramFiles(x86)%\gum2d47.tmp\goopdateres_zh-cn.dll
- %ProgramFiles(x86)%\gum2d47.tmp\goopdateres_vi.dll
- %ProgramFiles(x86)%\gum2d47.tmp\goopdateres_id.dll
- %ProgramFiles(x86)%\gum2d47.tmp\goopdateres_ur.dll
- %ProgramFiles(x86)%\gum2d47.tmp\goopdateres_tr.dll
- %ProgramFiles(x86)%\gum2d47.tmp\goopdateres_th.dll
- %ProgramFiles(x86)%\gum2d47.tmp\goopdateres_te.dll
- %ProgramFiles(x86)%\gum2d47.tmp\goopdateres_ta.dll
- %ProgramFiles(x86)%\gum2d47.tmp\goopdateres_sw.dll
- %ProgramFiles(x86)%\gum2d47.tmp\goopdateres_sv.dll
- %ProgramFiles(x86)%\gum2d47.tmp\goopdateres_sr.dll
- %ProgramFiles(x86)%\gum2d47.tmp\goopdateres_ru.dll
- %ProgramFiles(x86)%\gum2d47.tmp\goopdateres_sk.dll
- %ProgramFiles(x86)%\gum2d47.tmp\goopdateres_hu.dll
- %ProgramFiles(x86)%\gum2d47.tmp\goopdateres_ar.dll
- %ProgramFiles(x86)%\gum2d47.tmp\googlecrashhandler64.exe
- %ProgramFiles(x86)%\gum2d47.tmp\psuser_64.dll
- %ProgramFiles(x86)%\gum2d47.tmp\psuser.dll
- %ProgramFiles(x86)%\gum2d47.tmp\psmachine_64.dll
- %ProgramFiles(x86)%\gum2d47.tmp\psmachine.dll
- %ProgramFiles(x86)%\gum2d47.tmp\googleupdatecomregistershell64.exe
- %ProgramFiles(x86)%\gum2d47.tmp\googleupdateondemand.exe
- %ProgramFiles(x86)%\gum2d47.tmp\goopdateres_am.dll
- %ProgramFiles(x86)%\gum2d47.tmp\googleupdatebroker.exe
- %ProgramFiles(x86)%\gum2d47.tmp\npgoogleupdate3.dll
- %ProgramFiles(x86)%\gum2d47.tmp\goopdate.dll
- %ProgramFiles(x86)%\gum2d47.tmp\googlecrashhandler.exe
- %ProgramFiles(x86)%\gum2d47.tmp\googleupdate.exe
- %ProgramFiles(x86)%\gut2d48.tmp
- %TEMP%\chromesetup.exe
- %TEMP%\tmp57fe.tmp.exe
- %ProgramFiles(x86)%\gum2d47.tmp\googleupdatehelper.msi
- %ProgramFiles(x86)%\gum2d47.tmp\goopdateres_en-gb.dll
- %ProgramFiles(x86)%\gum2d47.tmp\goopdateres_hi.dll
- %ProgramFiles(x86)%\gum2d47.tmp\goopdateres_bg.dll
- %ProgramFiles(x86)%\gum2d47.tmp\goopdateres_gu.dll
- %ProgramFiles(x86)%\gum2d47.tmp\goopdateres_fr.dll
- %ProgramFiles(x86)%\gum2d47.tmp\goopdateres_fil.dll
- %ProgramFiles(x86)%\gum2d47.tmp\goopdateres_fi.dll
- %ProgramFiles(x86)%\gum2d47.tmp\goopdateres_fa.dll
- %ProgramFiles(x86)%\gum2d47.tmp\goopdateres_et.dll
- %ProgramFiles(x86)%\gum2d47.tmp\goopdateres_es-419.dll
- %ProgramFiles(x86)%\gum2d47.tmp\goopdateres_hr.dll
- %ProgramFiles(x86)%\gum2d47.tmp\goopdateres_es.dll
- %ProgramFiles(x86)%\gum2d47.tmp\goopdateres_en.dll
- %ProgramFiles(x86)%\gum2d47.tmp\goopdateres_el.dll
- %ProgramFiles(x86)%\gum2d47.tmp\goopdateres_de.dll
- %ProgramFiles(x86)%\gum2d47.tmp\goopdateres_da.dll
- %ProgramFiles(x86)%\gum2d47.tmp\goopdateres_cs.dll
- %ProgramFiles(x86)%\gum2d47.tmp\goopdateres_ca.dll
- %ProgramFiles(x86)%\gum2d47.tmp\goopdateres_bn.dll
- %TEMP%\tmp6f84.tmp.exe
- %ProgramFiles(x86)%\google\chrome\temp\source2164_1139068012\chrome.7z
- %TEMP%\tmp6f84.tmp.exe
- %TEMP%\tmp57fe.tmp.exe
- %TEMP%\{5cdced54-dc86-4705-85e8-5e84e165148f}-100.0.4896.127_chrome_installer.exe
- 'tools.google.com':443
- 'c.###nlink.golf':80
- 'ed####.me.gvt1.com':80
- http://c.###nlink.golf/sa/w.exe
- http://ed####.me.gvt1.com/edgedl/release2/chrome/koeiup3mgqmcikqtwgqsyeldma_100.0.4896.127/100.0.4896.127_chrome_installer.exe
- 'tools.google.com':443
- DNS ASK tools.google.com
- DNS ASK c.###nlink.golf
- DNS ASK ed####.me.gvt1.com
- '%TEMP%\icbwhxfw.exe'
- '%TEMP%\tmp57fe.tmp.exe'
- '%TEMP%\chromesetup.exe'
- '%ProgramFiles(x86)%\gum2d47.tmp\googleupdate.exe' /installsource taggedmi /install "appguid={8A69D345-D564-463C-AFF1-A69D9E530F96}&iid={3996D052-26B6-C178-E9E5-B86A7717C1CC}&lang=ru&browser=3&usagestats=0&appname=Google%20Chrome&needsadmin=pre...
- '%TEMP%\tmp6f84.tmp.exe'
- '%LOCALAPPDATA%\servicehub\tmp6f84.tmp.exe'
- '%LOCALAPPDATA%\servicehub\tmp57fe.tmp.exe'
- '%WINDIR%\syswow64\cmd.exe' /C chcp 65001 && ping 127.0.0.1 && schtasks /create /tn "tmp57FE.tmp" /sc MINUTE /tr "%LOCALAPPDATA%\ServiceHub\tmp57FE.tmp.exe" /rl HIGHEST /f && DEL /F /S /Q /A "%TEMP%\tmp57FE.tmp.exe" &&STA...' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /C chcp 65001 && ping 127.0.0.1 && schtasks /create /tn "tmp6F84.tmp" /sc MINUTE /tr "%LOCALAPPDATA%\ServiceHub\tmp6F84.tmp.exe" /rl HIGHEST /f && DEL /F /S /Q /A "%TEMP%\tmp6F84.tmp.exe" &&STA...' (with hidden window)
- '%LOCALAPPDATA%\servicehub\tmp57fe.tmp.exe' ' (with hidden window)
- '%LOCALAPPDATA%\servicehub\tmp6f84.tmp.exe' ' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /C chcp 65001 && ping 127.0.0.1 && schtasks /create /tn "tmp57FE.tmp" /sc MINUTE /tr "%LOCALAPPDATA%\ServiceHub\tmp57FE.tmp.exe" /rl HIGHEST /f && DEL /F /S /Q /A "%TEMP%\tmp57FE.tmp.exe" &&STA...
- '%ProgramFiles(x86)%\google\update\googleupdate.exe' /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB2ZXJzaW9uPSIxLjMuMjUuMTEiIHNoZWxsX3ZlcnNpb249IjEuMy4yNi45IiBpc21hY2hpbmU9IjEiIHNlc3Npb25pZD0ie0NFRUQxNUF...
- '%WINDIR%\syswow64\cmd.exe' /C chcp 65001 && ping 127.0.0.1 && schtasks /create /tn "tmp6F84.tmp" /sc MINUTE /tr "%LOCALAPPDATA%\ServiceHub\tmp6F84.tmp.exe" /rl HIGHEST /f && DEL /F /S /Q /A "%TEMP%\tmp6F84.tmp.exe" &&STA...
- '%ProgramFiles(x86)%\google\update\googleupdate.exe' /handoff "appguid={8A69D345-D564-463C-AFF1-A69D9E530F96}&iid={3996D052-26B6-C178-E9E5-B86A7717C1CC}&lang=ru&browser=3&usagestats=0&appname=Google%20Chrome&needsadmin=prefers" /installsource tag...
- '%WINDIR%\syswow64\chcp.com' 65001
- '%WINDIR%\syswow64\ping.exe' 127.0.0.1
- '%WINDIR%\syswow64\schtasks.exe' /create /tn "tmp6F84.tmp" /sc MINUTE /tr "%LOCALAPPDATA%\ServiceHub\tmp6F84.tmp.exe" /rl HIGHEST /f
- '%WINDIR%\syswow64\schtasks.exe' /create /tn "tmp57FE.tmp" /sc MINUTE /tr "%LOCALAPPDATA%\ServiceHub\tmp57FE.tmp.exe" /rl HIGHEST /f
- '<SYSTEM32>\taskeng.exe' {C2AB82EE-AAB0-4CFA-BF13-72A58D39CDC6} S-1-5-21-1960123792-2022915161-3775307078-1001:sorilcwrox\user:Interactive:[1]