Technical Information
- %WINDIR%\Tasks\WindowsUpdater.job
- '%TEMP%\1.tmp.exe' -silence -ptid=eit
- '%TEMP%\1.tmp.exe' (downloaded from the Internet)
- ClassName: 'PROCMON_WINDOW_CLASS' WindowName: ''
- %TEMP%\1.tmp.exe
- %APPDATA%\WindowsUpdater\Updater.exe
- %TEMP%\1.tmp.exe
- 'www.gi####uxiaowei.com':80
- '54.##4.246.97':80
- 'www.os##oft.com':80
- '54.##3.19.28':80
- 'localhost':1039
- http://www.gi####uxiaowei.com/home/eit_oursurfing.exe
- http://www.os##oft.com/download/updater.exe
- http://54.##3.19.28/cc.php
- http://54.##4.246.97/log/Outsurfing_IC5/install
- DNS ASK www.gi####uxiaowei.com
- DNS ASK www.os##oft.com
- ClassName: 'RegEdit_RegEdit' WindowName: ''