Technical Information
- '%WINDIR%\Jkliu.exe'
- '<Current directory>\Wiliu.exe'
- '%WINDIR%\Jkliu.exe' (downloaded from the Internet)
- ekrn.exe
- %WINDIR%\Jkliu.exe
- <Current directory>\Wiliu.exe
- <Current directory>\Wiliu.exe
- 'a1######20.148.8dns8.com':80
- 'dn###.3322.org':80
- dn###.3322.org/dy/wanm/wg46.exe
- DNS ASK a1######20.148.8dns8.com
- DNS ASK dn###.3322.org
- ClassName: '(null)' WindowName: 'ekrn.exe'
- ClassName: '(null)' WindowName: '360sd.exe'
- ClassName: '(null)' WindowName: '360rp.exe'