Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Chrome' = '"<SYSTEM32>\chrome.exe"'
- hidden files
- '%CommonProgramFiles%\chrome64.exe'
- '<SYSTEM32>\chrome.exe'
- '<SYSTEM32>\netsh.exe' firewall adds allowedprogram programs="%CommonProgramFiles%\chrome64.exe" names="Chrome 64
- '<SYSTEM32>\netsh.exe' firewall adds allowedprogram programs="<SYSTEM32>\chrome.exe" names="Chrome
- %CommonProgramFiles%\chrome64.exe
- <SYSTEM32>\chrome.exe
- %CommonProgramFiles%\chrome64.exe
- <SYSTEM32>\chrome.exe
- '<L####NET_GATEWAY>':5351
- '23#.#55.255.250':1900