Техническая информация
- %WINDIR%\syswow64\sohu.exe
- %WINDIR%\syswow64\sohu.exe
- %WINDIR%\syswow64\svehosd.exe
- %LOCALAPPDATA%\microsoft\internet explorer\msimgsiz.dat
- <DRIVERS>\etc\hosts
- 'tt##6.com':80
- 'hu###omains.com':443
- 'yy.com':80
- 'yy.com':443
- http://www.tt##6.com/
- http://www.tt##6.com/thread.php?fi####
- http://yy.com/5336/1705313832
- 'hu###omains.com':443
- 'yy.com':443
- DNS ASK tt##6.com
- DNS ASK hu###omains.com
- DNS ASK yy.com
- DNS ASK yz.##91pay.com
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- '%WINDIR%\syswow64\sohu.exe'
- '%WINDIR%\syswow64\svehosd.exe'