Техническая информация
- %WINDIR%\explorer.exe
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings] 'ProxyServer' = ''
- http://bu##########w.oss-cn-shanghai.aliyuncs.com/api/filegoto/64/o1_zz123
- http://ap##.#ame.qq.com/comm-htdocs/ip/get_ip.php
- http://bu##########w.oss-cn-shanghai.aliyuncs.com/api/general/thejs.json
- http://bu##########w.oss-cn-shanghai.aliyuncs.com/api/userconfig/uc_3512797a7988b25cd7975234b6afec19.json
- http://se#####pi.joloya.com/api/r/ip
- http://bu##########w.oss-cn-shanghai.aliyuncs.com/api/general/lsrpu.json
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt
- http://se#####pi.joloya.com/api/r/mcm
- DNS ASK bu##########w.oss-cn-shanghai.aliyuncs.com
- DNS ASK dh#mte
- DNS ASK ap##.#ame.qq.com
- DNS ASK sp#.#aidu.com
- DNS ASK se#####pi.joloya.com
- DNS ASK microsoft.com
- ClassName: 'ProgMan' WindowName: ''
- ClassName: 'SHELLDLL_DefView' WindowName: ''
- ClassName: 'SysListView32' WindowName: ''
- '<SYSTEM32>\ipconfig.exe' /flushdns' (со скрытым окном)
- '<SYSTEM32>\vdsldr.exe'
- '<SYSTEM32>\ipconfig.exe' /flushdns