Technical Information
- [<HKLM>\System\CurrentControlSet\Services\WinRing0_1_2_0] 'ImagePath' = '%TEMP%\WinRing0x64.sys'
- 'WinRing0_1_2_0' %TEMP%\WinRing0x64.sys
- %TEMP%\crashsender1403.exe
- %TEMP%\com_netease_skzdhlr_logo.png
- %TEMP%\com_netease_skzdhlr.png
- %TEMP%\com_netease_skzdhlr_background.png
- %WINDIR%\temp\udd6f5.tmp
- %WINDIR%\temp\uddff18.tmp
- %WINDIR%\temp\uddf73a.tmp
- %WINDIR%\temp\uddeed1.tmp
- %TEMP%\nemu-downloader.log
- %TEMP%\aria2c.exe
- %WINDIR%\temp\udded3.tmp
- %TEMP%\skin.zip
- %TEMP%\winring0x64.cat
- %TEMP%\winring0.inf
- %TEMP%\winring0x64.inf
- %TEMP%\winring0.sys
- %TEMP%\winring0x64.sys
- %TEMP%\config.ini
- %TEMP%\crashrpt_lang.ini
- %TEMP%\crashrpt1403.dll
- %TEMP%\crashrptprobe1403.dll
- %TEMP%\winring0.cat
- %WINDIR%\temp\udd16b0.tmp
- %WINDIR%\temp\uddeed1.tmp
- %WINDIR%\temp\uddf73a.tmp
- %WINDIR%\temp\uddff18.tmp
- %WINDIR%\temp\udd6f5.tmp
- %WINDIR%\temp\udded3.tmp
- %WINDIR%\temp\udd16b0.tmp
- http://g.##.#s.netease.com/nemu/file/5f8e3b1a2786fdb6b6a2b097kzvgihT202
- http://g.##.#s.netease.com/nemu/file/5f8e3b172786fde870757854SLVJWivg02
- DNS ASK mu##.##e.netease.com
- DNS ASK ap#.####3.nie.netease.com
- DNS ASK g.##.#s.netease.com