Technical Information
- 'im#.#ogou.com':80
- http://im#.#ogou.com/update/latest/new_version?tp###########################
- DNS ASK im#.#ogou.com
- '%WINDIR%\syswow64\cacls.exe' "%ALLUSERSPROFILE%\Tencent\QQUpdateMgr" /T /c /E /G everyone:F' (with hidden window)
- '%WINDIR%\syswow64\ipconfig.exe' /flushdns' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c del /F /Q "<Full path to file>"' (with hidden window)
- '%WINDIR%\syswow64\cacls.exe' "%ALLUSERSPROFILE%\Tencent\QQUpdateMgr" /T /c /E /G everyone:F
- '%WINDIR%\syswow64\ipconfig.exe' /flushdns
- '%WINDIR%\syswow64\cmd.exe' /c del /F /Q "<Full path to file>"