Техническая информация
- %WINDIR%\syswow64\sohu.exe
- ClassName: 'Regmonclass', WindowName: ''
- ClassName: 'Filemonclass', WindowName: ''
- %WINDIR%\syswow64\sohu.exe
- %LOCALAPPDATA%\microsoft\windows\history\history.ie5\mshist012023111820231119\index.dat
- %LOCALAPPDATA%\microsoft\internet explorer\msimgsiz.dat
- <DRIVERS>\etc\hosts
- 'tt##6.com':80
- 'it##.taobao.com':80
- 'ab####.cccpan.com':80
- 'hu###omains.com':443
- 'it##.taobao.com':443
- http://www.tt##6.com/
- http://www.tt##6.com/thread.php?fi####
- http://it##.taobao.com/item.htm?sp####################################
- http://dn#####an.cccpan.com/
- http://ab####.cccpan.com/
- 'hu###omains.com':443
- 'it##.taobao.com':443
- DNS ASK tt##6.com
- DNS ASK dn#####an.cccpan.com
- DNS ASK ab####.cccpan.com
- DNS ASK it##.taobao.com
- DNS ASK hu###omains.com
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- ClassName: '4823-00000029' WindowName: ''
- ClassName: '18467-41' WindowName: ''
- '%WINDIR%\syswow64\sohu.exe'