Техническая информация
- [HKLM\System\CurrentControlSet\Services\jhasjwlayz01] 'ImagePath' = '%TEMP%\48106E3C.res'
- 'jhasjwlayz01' %TEMP%\48106E3C.res
- %WINDIR%\syswow64\xilehlp.dll
- %WINDIR%\syswow64\xulehlp.dll
- %TEMP%\48106e3c.res
- %LOCALAPPDATA%\microsoft\windows\history\history.ie5\mshist012024120920241210\index.dat
- %TEMP%\48106e3c.res
- 'yy.##owan.com':80
- 'pe########e.radar.cloudflare.com':443
- 'yy.com':80
- 'yy.com':443
- http://yy.##owan.com/go.html
- http://yy.##owan.com/cdn-cgi/styles/main.css
- http://yy.com/
- 'pe########e.radar.cloudflare.com':443
- 'yy.com':443
- DNS ASK yy.##owan.com
- DNS ASK yy.com
- DNS ASK pe########e.radar.cloudflare.com
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''