Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '360Цч¶Ї·АУщ.exe' = '<SYSTEM32>\360Цч¶Ї·АУщ.exe'
- '<SYSTEM32>\PPTV(pplive)_forjieku_72790.exe'
- '<SYSTEM32>\PPTV(pplive)_forjieku_72790.exe' (загружен из сети Интернет)
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\a3[1]
- <SYSTEM32>\360Цч¶Ї·АУщ.exe
- <SYSTEM32>\PPTV(pplive)_forjieku_72790.exe
- 'xz#.#xooss.com':80
- 'localhost':1038
- 'u.##363.com':80
- xz#.#xooss.com/a3
- u.##363.com/pplfjk/PPTV(pplive)_forjieku_72790.exe
- DNS ASK xz#.#xooss.com
- DNS ASK u.##363.com
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'PPLiveGUI' WindowName: 'PPTV???????? V3.1.3.0042 ????'
- ClassName: 'MS_AutodialMonitor' WindowName: ''