Technical Information
- '%CommonProgramFiles%\Microsoft Shared\shadu.exe'
- '%CommonProgramFiles%\Microsoft Shared\zhuyea.exe'
- '%CommonProgramFiles%\Microsoft Shared\shadu.exe' (downloaded from the Internet)
- '%CommonProgramFiles%\Microsoft Shared\zhuyea.exe' (downloaded from the Internet)
- %CommonProgramFiles%\Microsoft Shared\shadu.exe
- %CommonProgramFiles%\Microsoft Shared\zhuyea.exe
- 'yu##.#anease.com':80
- 'localhost':1039
- yu##.#anease.com/shadu.exe
- yu##.#anease.com/zhuyea.exe
- DNS ASK yu##.#anease.com