Technical Information
- 'im#.#ogou.com':80
- 'mo####.baidu.com':80
- '11#.#36.153.0':80
- http://im#.#ogou.com/update/updateInfo.bzp
- http://mo####.baidu.com/update/updateInfo.bzp
- http://im#.#ogou.com/update/latest/new_version?tp#######
- DNS ASK im#.#ogou.com
- DNS ASK mo####.baidu.com
- '%WINDIR%\syswow64\cmd.exe' /c del /F /Q "<Full path to file>"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c del /F /Q "<Full path to file>"