Техническая информация
- %WINDIR%\explorer.exe
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings] 'ProxyServer' = ''
- %WINDIR%\fw.exe
- %WINDIR%\nviwhql.exe
- 'te###eidn.com':80
- 'ap##.#ame.qq.com':80
- 'cd#.#uilet.com':80
- '21######.sched.sma.tdnsv5.com':80
- 'sp#.#aidu.com':443
- 'gw##sh.com':80
- http://dd####kd.mmakd.ren/API/General/theseven
- http://dd####kd.mmakd.ren/api/userconfig/uc_2bd4378e4519b0a0f73b3cd533996173.json
- http://dd####kd.mmakd.ren/API/General/arearst
- http://dd####kd.mmakd.ren/API/General/lsrpu
- http://dd####kd.mmakd.ren/API/General/czcheck
- http://gw##sh.com/api/r/mcm
- 'sp#.#aidu.com':443
- DNS ASK te###eidn.com
- DNS ASK cd#.#qb3.com
- DNS ASK cd#.#uilet.com
- DNS ASK ap##.#ame.qq.com
- DNS ASK cd#.#ackow.com
- DNS ASK dd####kd.mmakd.ren
- DNS ASK cd#.#####w.com.cdn.dnsv1.com
- DNS ASK 21######.sched.sma.tdnsv5.com
- DNS ASK sp#.#aidu.com
- DNS ASK gw##sh.com
- DNS ASK microsoft.com
- ClassName: 'ProgMan' WindowName: ''
- ClassName: 'SHELLDLL_DefView' WindowName: ''
- ClassName: 'SysListView32' WindowName: ''
- '%WINDIR%\fw.exe'
- '%WINDIR%\nviwhql.exe'
- '%WINDIR%\fw.exe' ' (со скрытым окном)
- '%WINDIR%\nviwhql.exe' ' (со скрытым окном)
- '<SYSTEM32>\ipconfig.exe' /flushdns' (со скрытым окном)
- '<SYSTEM32>\reset.exe'
- '<SYSTEM32>\winlogon.exe'
- '<SYSTEM32>\ipconfig.exe' /flushdns