Technical Information
- <SYSTEM32>\tasks\microsoft\windows\hp2\printer
- <SYSTEM32>\tasks\microsoft\windows\hp2\restore
- %ProgramFiles(x86)%\xjconverter\file.7z
- %ProgramFiles(x86)%\xjconverter\imagecodec32.dll
- %ProgramFiles(x86)%\xjconverter\imagecodec64.dll
- %ProgramFiles(x86)%\xjconverter\uninst.exe
- %ProgramFiles(x86)%\xjconverter\xjconverter.exe
- %ALLUSERSPROFILE%\xjconverter\imagecodec64.dll
- %ProgramFiles(x86)%\xjconverter\file.7z
- 'vc###.laabei.com':80
- http://vc###.laabei.com/style_01/h_uc.css?ra#####################################################################################################################################################...
- DNS ASK vc###.laabei.com
- '%WINDIR%\syswow64\rundll32.exe' "%ALLUSERSPROFILE%\XJConverter\ImageCodec64.dll",ImageConvert
- '<SYSTEM32>\rundll32.exe' "%ALLUSERSPROFILE%\XJConverter\ImageCodec64.dll",ImageConvert