Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings] 'ProxyEnable' = '00000001'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings] 'ProxyServer' = '127.0.0.1:1080'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings] 'ProxyOverride' = 'localhost;127.*;10.*;172.16.*;172.17.*;172.18.*;172.19.*;172.20.*;172.21.*;172.22.*;172.23.*;172.24.*;172...
- [<HKLM>\SYSTEM\CURRENTCONTROLSET\HARDWARE PROFILES\CURRENT\Software\Microsoft\windows\CurrentVersion\Internet Settings] 'ProxyEnable' = '00000001'
- %TEMP%\shadowsocksr-dotnet4.0.exe
- %TEMP%\gui-config.json
- %TEMP%\dw.log
- %TEMP%\11ae28.dmp
- %TEMP%\temp\shadowsocksr-dotnet4.0.exe
- %TEMP%\temp\mgwz.dll
- %TEMP%\temp\privoxy.conf
- 'localhost':1080
- DNS ASK ra#.####ubusercontent.com
- '%TEMP%\shadowsocksr-dotnet4.0.exe'
- '%TEMP%\temp\shadowsocksr-dotnet4.0.exe' "%TEMP%\temp/privoxy.conf"
- '%TEMP%\temp\shadowsocksr-dotnet4.0.exe' "%TEMP%\temp/privoxy.conf"' (со скрытым окном)
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 480