Техническая информация
- '%PROGRAM_FILES%\xkss_50091168302.exe'
- '%PROGRAM_FILES%\qiannuo_009.exe'
- '%PROGRAM_FILES%\UUSEE_kb1003_Setup_164267.exe'
- '%PROGRAM_FILES%\qiannuo_009.exe' (загружен из сети Интернет)
- '%PROGRAM_FILES%\UUSEE_kb1003_Setup_164267.exe' (загружен из сети Интернет)
- '%PROGRAM_FILES%\xkss_50091168302.exe' (загружен из сети Интернет)
- %PROGRAM_FILES%\qiannuo_009.exe
- %PROGRAM_FILES%\xkss_50091168302.exe
- %PROGRAM_FILES%\UUSEE_kb1003_Setup_164267.exe
- 'do##.##inashangrui.com':80
- 'wu##.#####n-hangzhou.aliyuncs.com':80
- 'to#####014.f3322.org':20220
- 'localhost':1036
- 'do####ad.uusee.com':80
- wu##.#####n-hangzhou.aliyuncs.com/qd/qiannuo/qiannuo_009.exe
- do##.##inashangrui.com/sousuo/xkss_50091168302.exe
- do####ad.uusee.com/pop1/kb1003/UUSEE_kb1003_Setup_164267.exe
- DNS ASK do##.##inashangrui.com
- DNS ASK wu##.#####n-hangzhou.aliyuncs.com
- DNS ASK do####ad.uusee.com
- DNS ASK to#####014.f3322.org
- ClassName: 'MS_WebcheckMonitor' WindowName: '(null)'
- ClassName: 'MS_AutodialMonitor' WindowName: '(null)'