Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\Windows_rejoice2008_201] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\SVKP] 'Start' = '00000002'
- '<SYSTEM32>\dumprep.exe' 3684 -dm 7 7 %TEMP%\WER5b3f.dir00\calc.exe.hdmp 16325836412027088
- '<SYSTEM32>\dumprep.exe' 3684 -dm 7 7 %TEMP%\WER5b3f.dir00\calc.exe.mdmp 16325836412027076
- '<SYSTEM32>\dumprep.exe' 3736 -dm 7 7 %TEMP%\WER73de.dir00\calc.exe.mdmp 16325836412027076
- '<SYSTEM32>\dumprep.exe' 3796 -dm 7 7 %TEMP%\WERac86.dir00\calc.exe.mdmp 16325836412027076
- '<SYSTEM32>\dumprep.exe' 3736 -dm 7 7 %TEMP%\WER73de.dir00\calc.exe.hdmp 16325836412027088
- '<SYSTEM32>\dumprep.exe' 3628 -dm 7 7 %TEMP%\WER210a.dir00\calc.exe.hdmp 16325836412027088
- '<SYSTEM32>\dumprep.exe' 3524 -dm 7 7 %TEMP%\WERd370.dir00\calc.exe.hdmp 16325836412027088
- '<SYSTEM32>\dumprep.exe' 3524 -dm 7 7 %TEMP%\WERd370.dir00\calc.exe.mdmp 16325836412027076
- '<SYSTEM32>\dumprep.exe' 3576 -dm 7 7 %TEMP%\WER0b46.dir00\calc.exe.mdmp 16325836412027076
- '<SYSTEM32>\dumprep.exe' 3628 -dm 7 7 %TEMP%\WER210a.dir00\calc.exe.mdmp 16325836412027076
- '<SYSTEM32>\dumprep.exe' 3576 -dm 7 7 %TEMP%\WER0b46.dir00\calc.exe.hdmp 16325836412027088
- '<SYSTEM32>\dumprep.exe' 3796 -dm 7 7 %TEMP%\WERac86.dir00\calc.exe.hdmp 16325836412027088
- '<SYSTEM32>\dumprep.exe' 4024 -dm 7 7 %TEMP%\WER311a.dir00\calc.exe.hdmp 16325836412027088
- '<SYSTEM32>\dumprep.exe' 4024 -dm 7 7 %TEMP%\WER311a.dir00\calc.exe.mdmp 16325836412027076
- '<SYSTEM32>\dumprep.exe' 4076 -dm 7 7 %TEMP%\WER6991.dir00\calc.exe.mdmp 16325836412027076
- '<SYSTEM32>\dumprep.exe' 2052 -dm 7 7 %TEMP%\WER9b5d.dir00\calc.exe.mdmp 16325836412027076
- '<SYSTEM32>\dumprep.exe' 4076 -dm 7 7 %TEMP%\WER6991.dir00\calc.exe.hdmp 16325836412027088
- '<SYSTEM32>\dumprep.exe' 3972 -dm 7 7 %TEMP%\WER187b.dir00\calc.exe.hdmp 16325836412027088
- '<SYSTEM32>\dumprep.exe' 3860 -dm 7 7 %TEMP%\WERc51a.dir00\calc.exe.hdmp 16325836412027088
- '<SYSTEM32>\dumprep.exe' 3860 -dm 7 7 %TEMP%\WERc51a.dir00\calc.exe.mdmp 16325836412027076
- '<SYSTEM32>\dumprep.exe' 3912 -dm 7 7 %TEMP%\WERfd2e.dir00\calc.exe.mdmp 16325836412027076
- '<SYSTEM32>\dumprep.exe' 3972 -dm 7 7 %TEMP%\WER187b.dir00\calc.exe.mdmp 16325836412027076
- '<SYSTEM32>\dumprep.exe' 3912 -dm 7 7 %TEMP%\WERfd2e.dir00\calc.exe.hdmp 16325836412027088
- '<SYSTEM32>\dumprep.exe' 3472 -dm 7 7 %TEMP%\WERba23.dir00\calc.exe.hdmp 16325836412027088
- '<SYSTEM32>\dumprep.exe' 3004 -dm 7 7 %TEMP%\WER89cc.dir00\calc.exe.hdmp 16325836412027088
- '<SYSTEM32>\dumprep.exe' 3004 -dm 7 7 %TEMP%\WER89cc.dir00\calc.exe.mdmp 16325836412027076
- '<SYSTEM32>\dumprep.exe' 3060 -dm 7 7 %TEMP%\WERa51a.dir00\calc.exe.mdmp 16325836412027076
- '<SYSTEM32>\dumprep.exe' 3112 -dm 7 7 %TEMP%\WERdc0a.dir00\calc.exe.mdmp 16325836412027076
- '<SYSTEM32>\dumprep.exe' 3060 -dm 7 7 %TEMP%\WERa51a.dir00\calc.exe.hdmp 16325836412027088
- '<SYSTEM32>\dumprep.exe' 2940 -dm 7 7 %TEMP%\WER5552.dir00\calc.exe.hdmp 16325836412027096
- '<SYSTEM32>\dumprep.exe' 2896 -dm 7 7 %TEMP%\WER3893.dir00\calc.exe.mdmp 16325836412027076
- '<SYSTEM32>\calc.exe'
- '<SYSTEM32>\dumprep.exe' 2896 -dm 7 7 %TEMP%\WER3893.dir00\calc.exe.hdmp 16325836412027096
- '<SYSTEM32>\dumprep.exe' 2940 -dm 7 7 %TEMP%\WER5552.dir00\calc.exe.mdmp 16325836412027076
- '<SYSTEM32>\rundll32.exe' <SYSTEM32>\sysdm.cpl,NoExecuteProcessException <SYSTEM32>\calc.exe
- '<SYSTEM32>\dumprep.exe' 3112 -dm 7 7 %TEMP%\WERdc0a.dir00\calc.exe.hdmp 16325836412027088
- '<SYSTEM32>\dumprep.exe' 3352 -dm 7 7 %TEMP%\WER6766.dir00\calc.exe.hdmp 16325836412027088
- '<SYSTEM32>\dumprep.exe' 3352 -dm 7 7 %TEMP%\WER6766.dir00\calc.exe.mdmp 16325836412027076
- '<SYSTEM32>\dumprep.exe' 3412 -dm 7 7 %TEMP%\WER9c74.dir00\calc.exe.mdmp 16325836412027076
- '<SYSTEM32>\dumprep.exe' 3472 -dm 7 7 %TEMP%\WERba23.dir00\calc.exe.mdmp 16325836412027076
- '<SYSTEM32>\dumprep.exe' 3412 -dm 7 7 %TEMP%\WER9c74.dir00\calc.exe.hdmp 16325836412027088
- '<SYSTEM32>\dumprep.exe' 3300 -dm 7 7 %TEMP%\WER4986.dir00\calc.exe.hdmp 16325836412027088
- '<SYSTEM32>\dumprep.exe' 3192 -dm 7 7 %TEMP%\WERfba6.dir00\calc.exe.hdmp 16325836412027088
- '<SYSTEM32>\dumprep.exe' 3192 -dm 7 7 %TEMP%\WERfba6.dir00\calc.exe.mdmp 16325836412027076
- '<SYSTEM32>\dumprep.exe' 3248 -dm 7 7 %TEMP%\WER11d7.dir00\calc.exe.mdmp 16325836412027076
- '<SYSTEM32>\dumprep.exe' 3300 -dm 7 7 %TEMP%\WER4986.dir00\calc.exe.mdmp 16325836412027076
- '<SYSTEM32>\dumprep.exe' 3248 -dm 7 7 %TEMP%\WER11d7.dir00\calc.exe.hdmp 16325836412027088
- <SYSTEM32>\calc.exe
- %TEMP%\WER5b3f.dir00\calc.exe.hdmp
- %TEMP%\WER5b3f.dir00\appcompat.txt
- %TEMP%\WER5b3f.dir00\calc.exe.mdmp
- %TEMP%\WER210a.dir00\appcompat.txt
- %TEMP%\WER210a.dir00\manifest.txt
- %TEMP%\WER5b3f.dir00\manifest.txt
- %TEMP%\WER73de.dir00\manifest.txt
- %TEMP%\WERac86.dir00\calc.exe.mdmp
- %TEMP%\WER73de.dir00\appcompat.txt
- %TEMP%\WER73de.dir00\calc.exe.mdmp
- %TEMP%\WER73de.dir00\calc.exe.hdmp
- %TEMP%\WER210a.dir00\calc.exe.hdmp
- %TEMP%\WERd370.dir00\calc.exe.hdmp
- %TEMP%\WERd370.dir00\appcompat.txt
- %TEMP%\WERd370.dir00\calc.exe.mdmp
- %TEMP%\WERba23.dir00\appcompat.txt
- %TEMP%\WERba23.dir00\manifest.txt
- %TEMP%\WERd370.dir00\manifest.txt
- %TEMP%\WER0b46.dir00\manifest.txt
- %TEMP%\WER210a.dir00\calc.exe.mdmp
- %TEMP%\WER0b46.dir00\appcompat.txt
- %TEMP%\WER0b46.dir00\calc.exe.mdmp
- %TEMP%\WER0b46.dir00\calc.exe.hdmp
- %TEMP%\WER311a.dir00\calc.exe.mdmp
- %TEMP%\WER311a.dir00\calc.exe.hdmp
- %TEMP%\WER187b.dir00\manifest.txt
- %TEMP%\WER187b.dir00\calc.exe.hdmp
- %TEMP%\WER187b.dir00\appcompat.txt
- %TEMP%\WER311a.dir00\appcompat.txt
- %TEMP%\WER6991.dir00\appcompat.txt
- %TEMP%\WER6991.dir00\manifest.txt
- %TEMP%\WER6991.dir00\calc.exe.hdmp
- %TEMP%\WER311a.dir00\manifest.txt
- %TEMP%\WER6991.dir00\calc.exe.mdmp
- %TEMP%\WER187b.dir00\calc.exe.mdmp
- %TEMP%\WERc51a.dir00\calc.exe.mdmp
- %TEMP%\WERc51a.dir00\calc.exe.hdmp
- %TEMP%\WERac86.dir00\manifest.txt
- %TEMP%\WERac86.dir00\calc.exe.hdmp
- %TEMP%\WERac86.dir00\appcompat.txt
- %TEMP%\WERc51a.dir00\appcompat.txt
- %TEMP%\WERfd2e.dir00\appcompat.txt
- %TEMP%\WERfd2e.dir00\manifest.txt
- %TEMP%\WERfd2e.dir00\calc.exe.hdmp
- %TEMP%\WERc51a.dir00\manifest.txt
- %TEMP%\WERfd2e.dir00\calc.exe.mdmp
- %TEMP%\WER89cc.dir00\manifest.txt
- %TEMP%\WERa51a.dir00\calc.exe.mdmp
- %TEMP%\WER89cc.dir00\appcompat.txt
- %TEMP%\WER89cc.dir00\calc.exe.mdmp
- %TEMP%\WER89cc.dir00\calc.exe.hdmp
- %TEMP%\WERa51a.dir00\calc.exe.hdmp
- %TEMP%\WERdc0a.dir00\calc.exe.hdmp
- %TEMP%\WERdc0a.dir00\appcompat.txt
- %TEMP%\WERdc0a.dir00\calc.exe.mdmp
- %TEMP%\WERa51a.dir00\appcompat.txt
- %TEMP%\WERa51a.dir00\manifest.txt
- %TEMP%\WER5552.dir00\manifest.txt
- <SYSTEM32>\_rejoice082.exe
- %TEMP%\WER3893.dir00\calc.exe.mdmp
- %WINDIR%\rejoice082.exe
- <SYSTEM32>\SVKP.sys
- %WINDIR%\FieleWay.txt
- %TEMP%\WER3893.dir00\calc.exe.hdmp
- %TEMP%\WER5552.dir00\calc.exe.hdmp
- %TEMP%\WER5552.dir00\appcompat.txt
- %TEMP%\WER5552.dir00\calc.exe.mdmp
- %TEMP%\WER3893.dir00\appcompat.txt
- %TEMP%\WER3893.dir00\manifest.txt
- %TEMP%\WER6766.dir00\appcompat.txt
- %TEMP%\WER6766.dir00\manifest.txt
- %TEMP%\WER6766.dir00\calc.exe.hdmp
- %TEMP%\WER4986.dir00\manifest.txt
- %TEMP%\WER6766.dir00\calc.exe.mdmp
- %TEMP%\WER9c74.dir00\calc.exe.mdmp
- %TEMP%\WERba23.dir00\calc.exe.mdmp
- %TEMP%\WERba23.dir00\calc.exe.hdmp
- %TEMP%\WER9c74.dir00\manifest.txt
- %TEMP%\WER9c74.dir00\calc.exe.hdmp
- %TEMP%\WER9c74.dir00\appcompat.txt
- %TEMP%\WER4986.dir00\appcompat.txt
- %TEMP%\WERfba6.dir00\appcompat.txt
- %TEMP%\WERfba6.dir00\manifest.txt
- %TEMP%\WERfba6.dir00\calc.exe.hdmp
- %TEMP%\WERdc0a.dir00\manifest.txt
- %TEMP%\WERfba6.dir00\calc.exe.mdmp
- %TEMP%\WER11d7.dir00\calc.exe.mdmp
- %TEMP%\WER4986.dir00\calc.exe.mdmp
- %TEMP%\WER4986.dir00\calc.exe.hdmp
- %TEMP%\WER11d7.dir00\manifest.txt
- %TEMP%\WER11d7.dir00\calc.exe.hdmp
- %TEMP%\WER11d7.dir00\appcompat.txt
- <SYSTEM32>\_rejoice082.exe
- %WINDIR%\rejoice082.exe
- %WINDIR%\FieleWay.txt
- 'ld######ua.googlepages.com':80
- ld######ua.googlepages.com/sx.txt
- DNS ASK ld######ua.googlepages.com
- ClassName: 'TSxre2008' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'TAppBuilder' WindowName: '(null)'
- ClassName: 'MS_WINHELP' WindowName: '(null)'