Техническая информация
- NtWriteVirtualMemory, драйвер-обработчик: xinlan.sys
- NtReadVirtualMemory, драйвер-обработчик: xinlan.sys
- NtQuerySystemInformation, драйвер-обработчик: xinlan.sys
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\19016050[1]
- C:\xinlan.sys
- C:\xinlan.sys
- C:\xinlan.sys
- 'yy.com':80
- 'localhost':1036
- yy.com/19016050
- DNS ASK yy.com
- ClassName: '(null)' WindowName: 'WDKeyMonitorABC.exe'
- ClassName: '(null)' WindowName: 'QQLogin.exe'
- ClassName: '(null)' WindowName: 'rundll32.exe'
- ClassName: '(null)' WindowName: 'IAStorDataMgrSvc.exe'
- ClassName: 'MS_WebcheckMonitor' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: '(null)' WindowName: 'DNFfb.exe'
- ClassName: 'MS_AutodialMonitor' WindowName: '(null)'
- ClassName: '(null)' WindowName: 'Txplatform.exe'
- ClassName: '(null)' WindowName: 'QQDL.exe'
- ClassName: '(null)' WindowName: 'TenSafe_1.exe'
- ClassName: '(null)' WindowName: 'TenSafe_2.exe'
- ClassName: '(null)' WindowName: 'QQExternal.exe'
- ClassName: '(null)' WindowName: 'WDCertM_ABC.exe'
- ClassName: '(null)' WindowName: 'SougouCloud.exe'
- ClassName: '(null)' WindowName: 'Tencentdl.exe'