Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '530238543e28b649e18feec9528b1842' = '"%TEMP%\intelHD.exe" ..'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '530238543e28b649e18feec9528b1842' = '"%TEMP%\intelHD.exe" ..'
- %HOMEPATH%\Start Menu\Programs\Startup\530238543e28b649e18feec9528b1842.exe
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '%TEMP%\intelHD.exe' = '%TEMP%\intelHD.exe:*:Enabled:intelHD.exe'
- '%TEMP%\intelHD.exe'
- '<SYSTEM32>\netsh.exe' firewall add allowedprogram "%TEMP%\intelHD.exe" "intelHD.exe" ENABLE
- %TEMP%\intelHD.exe
- 'to####e.ddns.net':5053
- DNS ASK to####e.ddns.net