Technical Information
- %TEMP%\ede7.tmp\ede8.tmp\ede9.bat
- %HOMEPATH%\desktop\xdd.bat
- %TEMP%\841e.tmp
- %TEMP%\etilqs_vcazikihrgh6oba
- %TEMP%\e630.tmp
- %TEMP%\scoped_dir_820_13695\841e.tmp
- %TEMP%\scoped_dir_820_13695\crx_install\manifest.json
- %TEMP%\etilqs_wk8kongaalpdpbm
- %HOMEPATH%\desktop\xdd.bat
- %TEMP%\ede7.tmp\ede8.tmp\ede9.bat
- %TEMP%\e630.tmp
- %TEMP%\scoped_dir_820_13695\841e.tmp
- %TEMP%\scoped_dir_820_13695\decoded_images
- %TEMP%\scoped_dir_820_13695\decoded_message_catalogs
- %TEMP%\841e.tmp
- 'clients4.google.com':443
- 'ht####2.adtng.com':443
- 'gs##tic.com':443
- 'ht####.trafficjunky.net':443
- 'st###.#.doubleclick.net':443
- 'hw####.trafficjunky.net':443
- 'ad##.#ontentabc.com':443
- 'ad#.###fficjunky.net':443
- 'ss.##ncdn.com':443
- 'cd######llimg.phncdn.com':443
- 'cs.##ncdn.com':443
- 'go#####analytics.com':443
- 'ei.##ncdn.com':443
- 'di.##ncdn.com':443
- 'st####.trafficjunky.com':443
- 'r4######5hnekn7z.gvt1.com':80
- 're####ctor.gvt1.com':80
- 'gs##tic.com':80
- 'tr######e.googleapis.com':443
- 'cz.##rnhub.com':443
- 'clients2.google.com':443
- 'hu##.#ornhub.com':443
- 'cl.##ncdn.com':443
- 'clients4.google.com':443
- 'gs##tic.com':443
- 'st###.#.doubleclick.net':443
- 'hw#####.trafficjunky.net':443
- 'a.##tng.com':443
- 'ad#.###fficjunky.net':443
- 'cd######llimg.phncdn.com':443
- 'go#####analytics.com':443
- 'hu##.#ornhub.com':443
- 'ei.##ncdn.com':443
- 'di.##ncdn.com':443
- 'st####.trafficjunky.com':443
- 'google.com':443
- 'go###eapis.com':443
- 'cz.##rnhub.com':443
- 'clients2.google.com':443
- 'ci.##ncdn.com':443
- 'st#####.googleapis.com':443
- DNS ASK clients2.google.com
- DNS ASK apis.google.com
- DNS ASK as.##ncdn.com
- DNS ASK ci.##ncdn.com
- DNS ASK cs.##ncdn.com
- DNS ASK fo###.#oogleapis.com
- DNS ASK hw####2.adtng.com
- DNS ASK hw#####.trafficjunky.net
- DNS ASK ai.##ncdn.com
- DNS ASK aj##.#oogleapis.com
- DNS ASK m1.##img.net
- DNS ASK vz####2.adtng.com
- DNS ASK vz#####.trafficjunky.net
- DNS ASK st###.#.doubleclick.net
- DNS ASK hw####.trafficjunky.net
- DNS ASK ht####.trafficjunky.net
- DNS ASK go##le.nl
- DNS ASK ht####2.adtng.com
- DNS ASK m2.##img.net
- DNS ASK me###.#rafficjunky.net
- DNS ASK ad##.#ontentabc.com
- DNS ASK ad#.###fficjunky.net
- DNS ASK a.##tng.com
- DNS ASK google.com
- DNS ASK go##le.ru
- DNS ASK go###eapis.com
- DNS ASK cz.##rnhub.com
- DNS ASK tr######e.googleapis.com
- DNS ASK gs##tic.com
- DNS ASK re####ctor.gvt1.com
- DNS ASK r4######5hnekn7z.gvt1.com
- DNS ASK clients4.google.com
- DNS ASK st#####.googleapis.com
- DNS ASK ei.##ncdn.com
- DNS ASK po##hub.com
- DNS ASK st####.trafficjunky.com
- DNS ASK di.##ncdn.com
- DNS ASK hu##.#ornhub.com
- DNS ASK go#####analytics.com
- DNS ASK cd######llimg.phncdn.com
- DNS ASK ss.##ncdn.com
- DNS ASK clients3.google.com
- DNS ASK cl.##ncdn.com
- 'google.com':443
- ClassName: 'Chrome_MessageWindow' WindowName: '%LOCALAPPDATA%\Google\Chrome\User Data'
- '<SYSTEM32>\cmd.exe' /c "%TEMP%\EDE7.tmp\EDE8.tmp\EDE9.bat <Full path to file>"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "%TEMP%\EDE7.tmp\EDE8.tmp\EDE9.bat <Full path to file>"
- '<SYSTEM32>\attrib.exe' +H +S XDD.bat
- '<SYSTEM32>\cmd.exe' /K XDD.bat
- '<SYSTEM32>\msg.exe' * Zde mas neco pro labuzniky
- '%ProgramFiles(x86)%\google\chrome\application\chrome.exe' https://cz.pornhub.com/
- '%ProgramFiles(x86)%\google\chrome\application\chrome.exe' --type=gpu-process --channel="820.0.545576988\736377192" --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,19,42 --gpu-vendor-id=0x0000 --gpu-device-id=0x0000 --gpu-driver-vendor --gpu-...
- '%ProgramFiles(x86)%\google\chrome\application\chrome.exe' --type=gpu-process --channel="1116.0.1147268368\2049300299" --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,19,42 --gpu-vendor-id=0x0000 --gpu-device-id=0x0000 --gpu-driver-vendor --g...
- '%ProgramFiles(x86)%\google\chrome\application\chrome.exe' --type=gpu-process --channel="2468.0.465307164\76560078" --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,19,42 --gpu-vendor-id=0x0000 --gpu-device-id=0x0000 --gpu-driver-vendor --gpu-...
- '%ProgramFiles(x86)%\google\chrome\application\chrome.exe' --type=gpu-process --channel="2896.0.1020512561\965418315" --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,19,42 --gpu-vendor-id=0x0000 --gpu-device-id=0x0000 --gpu-driver-vendor --gp...
- '%ProgramFiles(x86)%\google\chrome\application\chrome.exe' --type=renderer --enable-deferred-image-decoding --lang=ru --force-fieldtrials="BackgroundRendererProcesses/Disallow/BrowserBlacklist/Enabled/*CTRequiredForEVTrial/RequirementEnforced/CaptivePo...
- '%ProgramFiles(x86)%\google\chrome\application\chrome.exe' --type=renderer --enable-deferred-image-decoding --lang=ru --force-fieldtrials="BackgroundRendererProcesses/Disallow/*BrowserBlacklist/Enabled/*CTRequiredForEVTrial/RequirementEnforced/CaptiveP...