Technical Information
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Java Platform SE javaupdater_platform.exe' = '%APPDATA%\Oracle\javaupdater_platform.exe'
- %APPDATA%\oracle\readme.txt
- %APPDATA%\oracle\version.txt
- %APPDATA%\oracle\javaupdater.exe
- %APPDATA%\oracle\.java_initialized
- %APPDATA%\oracle\java_update.log
- from %APPDATA%\oracle\javaupdater.exe to %APPDATA%\oracle\javaruntime_update.exe
- from %APPDATA%\oracle\javaplatform_update.exe to %APPDATA%\oracle\javasupport_service.exe
- from %APPDATA%\oracle\javaplugin_update.exe to %APPDATA%\oracle\javaplatform.exe
- from %APPDATA%\oracle\javaupdater.exe to %APPDATA%\oracle\javaruntime_service.exe
- from %APPDATA%\oracle\javaservice_update.exe to %APPDATA%\oracle\javaservice_platform.exe
- from %APPDATA%\oracle\javaupdaterw.exe to %APPDATA%\oracle\javaservice_update.exe
- from %APPDATA%\oracle\javaplatform_platform.exe to %APPDATA%\oracle\javasupport_update.exe
- from %APPDATA%\oracle\javaplatform_platform.exe to %APPDATA%\oracle\javaplugin_platform.exe
- from %APPDATA%\oracle\javaupdater_service.exe to %APPDATA%\oracle\javaupdater_platform.exe
- from %APPDATA%\oracle\javaruntime.exe to %APPDATA%\oracle\javaupdater_update.exe
- from %APPDATA%\oracle\javasupport.exe to %APPDATA%\oracle\javaruntime.exe
- from %APPDATA%\oracle\javaservice_service.exe to %APPDATA%\oracle\javaplatform_service.exe
- from %APPDATA%\oracle\javaruntimew.exe to %APPDATA%\oracle\javaservice_service.exe
- from %APPDATA%\oracle\javaruntime_platform.exe to %APPDATA%\oracle\javaruntimew.exe
- from %APPDATA%\oracle\javaplugin_service.exe to %APPDATA%\oracle\javaruntime_platform.exe
- from %APPDATA%\oracle\javaplatformw.exe to %APPDATA%\oracle\javasupportw.exe
- from %APPDATA%\oracle\javapluginw.exe to %APPDATA%\oracle\javaplatformw.exe
- from %APPDATA%\oracle\javaplatform_update.exe to %APPDATA%\oracle\javapluginw.exe
- from %APPDATA%\oracle\javaplugin_service.exe to %APPDATA%\oracle\javasupport.exe
- from %APPDATA%\oracle\javaupdater_service.exe to %APPDATA%\oracle\javaplugin_service.exe
- from %APPDATA%\oracle\javaplatform_update.exe to %APPDATA%\oracle\javaupdater_service.exe
- from %APPDATA%\oracle\javaplugin.exe to %APPDATA%\oracle\javaplatform_platform.exe
- from %APPDATA%\oracle\javaplugin_update.exe to %APPDATA%\oracle\javaplugin.exe
- from %APPDATA%\oracle\javaupdaterw.exe to %APPDATA%\oracle\javaplugin_update.exe
- from %APPDATA%\oracle\javaplatform_update.exe to %APPDATA%\oracle\javaupdaterw.exe
- from %APPDATA%\oracle\javaruntime_update.exe to %APPDATA%\oracle\javaplatform_update.exe
- from %APPDATA%\oracle\javaruntime_service.exe to %APPDATA%\oracle\javaservice.exe
- from %APPDATA%\oracle\javasupportw.exe to %APPDATA%\oracle\javasupport_platform.exe
- %APPDATA%\oracle\javaplatform_update.exe
- %APPDATA%\oracle\javasupport_service.exe
- %APPDATA%\oracle\javaservice.exe
- %APPDATA%\oracle\javaupdater_platform.exe
- %APPDATA%\oracle\javaplugin_platform.exe
- %APPDATA%\oracle\javaservice_platform.exe
- %APPDATA%\oracle\javaplatform_service.exe
- %APPDATA%\oracle\javaruntime_service.exe
- %APPDATA%\oracle\javaplatformw.exe
- %APPDATA%\oracle\javaruntime.exe
- %APPDATA%\oracle\javasupport_update.exe
- %APPDATA%\oracle\javaservice_service.exe
- %APPDATA%\oracle\javaruntimew.exe
- %APPDATA%\oracle\javaupdater.exe
- %APPDATA%\oracle\javaplugin.exe
- %APPDATA%\oracle\javaupdaterw.exe
- %APPDATA%\oracle\javaplugin_update.exe
- %APPDATA%\oracle\javaplatform_platform.exe
- %APPDATA%\oracle\javaupdater_service.exe
- %APPDATA%\oracle\javasupportw.exe
- %APPDATA%\oracle\javasupport.exe
- %APPDATA%\oracle\javaplugin_service.exe
- %APPDATA%\oracle\javaruntime_update.exe
- %APPDATA%\oracle\javapluginw.exe
- 'go###.fechrise.fun':9090
- DNS ASK go###.fechrise.fun
- '%APPDATA%\oracle\javaupdater.exe'
- '%APPDATA%\oracle\javaservice.exe'
- '%APPDATA%\oracle\javasupport_service.exe'
- '%APPDATA%\oracle\javaplatform.exe'
- '%APPDATA%\oracle\javaruntime_service.exe'
- '%APPDATA%\oracle\javaservice_platform.exe'
- '%APPDATA%\oracle\javaservice_update.exe'
- '%APPDATA%\oracle\javasupport_update.exe'
- '%APPDATA%\oracle\javaplugin_platform.exe'
- '%APPDATA%\oracle\javaupdater_platform.exe'
- '%APPDATA%\oracle\javaupdater_update.exe'
- '%APPDATA%\oracle\javaruntime.exe'
- '%APPDATA%\oracle\javaplatform_service.exe'
- '%APPDATA%\oracle\javaservice_service.exe'
- '%APPDATA%\oracle\javaruntimew.exe'
- '%APPDATA%\oracle\javaruntime_platform.exe'
- '%APPDATA%\oracle\javasupportw.exe'
- '%APPDATA%\oracle\javaplatformw.exe'
- '%APPDATA%\oracle\javapluginw.exe'
- '%APPDATA%\oracle\javasupport.exe'
- '%APPDATA%\oracle\javaplugin_service.exe'
- '%APPDATA%\oracle\javaupdater_service.exe'
- '%APPDATA%\oracle\javaplatform_platform.exe'
- '%APPDATA%\oracle\javaplugin.exe'
- '%APPDATA%\oracle\javaplugin_update.exe'
- '%APPDATA%\oracle\javaupdaterw.exe'
- '%APPDATA%\oracle\javaplatform_update.exe'
- '%APPDATA%\oracle\javaruntime_update.exe'
- '%APPDATA%\oracle\javasupport_platform.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Set-ItemProperty -Path 'HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run' -Name 'Java Platform SE javaupdater_platform.exe' -Value '"%APPDATA%\Oracle\javaupdater_platform.exe"'"
- '<SYSTEM32>\reg.exe' query HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /v "Java Platform SE javaupdater_platform.exe"
- '%APPDATA%\oracle\javaservice.exe' ' (with hidden window)
- '%APPDATA%\oracle\javasupport_service.exe' ' (with hidden window)
- '%APPDATA%\oracle\javaplatform.exe' ' (with hidden window)
- '%APPDATA%\oracle\javaruntime_service.exe' ' (with hidden window)
- '%APPDATA%\oracle\javaservice_platform.exe' ' (with hidden window)
- '%APPDATA%\oracle\javaservice_update.exe' ' (with hidden window)
- '%APPDATA%\oracle\javasupport_update.exe' ' (with hidden window)
- '%APPDATA%\oracle\javaplugin_platform.exe' ' (with hidden window)
- '%APPDATA%\oracle\javaupdater_platform.exe' ' (with hidden window)
- '%APPDATA%\oracle\javaupdater_update.exe' ' (with hidden window)
- '%APPDATA%\oracle\javaruntime.exe' ' (with hidden window)
- '%APPDATA%\oracle\javaplatform_service.exe' ' (with hidden window)
- '%APPDATA%\oracle\javaservice_service.exe' ' (with hidden window)
- '%APPDATA%\oracle\javaruntimew.exe' ' (with hidden window)
- '%APPDATA%\oracle\javaruntime_platform.exe' ' (with hidden window)
- '%APPDATA%\oracle\javasupportw.exe' ' (with hidden window)
- '%APPDATA%\oracle\javaplatformw.exe' ' (with hidden window)
- '%APPDATA%\oracle\javapluginw.exe' ' (with hidden window)
- '%APPDATA%\oracle\javasupport.exe' ' (with hidden window)
- '%APPDATA%\oracle\javaplugin_service.exe' ' (with hidden window)
- '%APPDATA%\oracle\javaupdater_service.exe' ' (with hidden window)
- '%APPDATA%\oracle\javaplatform_platform.exe' ' (with hidden window)
- '%APPDATA%\oracle\javaplugin.exe' ' (with hidden window)
- '%APPDATA%\oracle\javaplugin_update.exe' ' (with hidden window)
- '%APPDATA%\oracle\javaupdaterw.exe' ' (with hidden window)
- '%APPDATA%\oracle\javaplatform_update.exe' ' (with hidden window)
- '%APPDATA%\oracle\javaruntime_update.exe' ' (with hidden window)
- '%APPDATA%\oracle\javasupport_platform.exe' ' (with hidden window)
- '%APPDATA%\oracle\javaupdater.exe' ' (with hidden window)