Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\Windows_qq.exe] 'Start' = '00000002'
- %PROGRAM_FILES%\qq.exe
- <SYSTEM32>\cmd.exe /c "%PROGRAM_FILES%\DelSvel.bat"
- <SYSTEM32>\dumprep.exe 2776 -dm 7 7 "%TEMP%\WERf24b.dir00\calc.exe.mdmp" 16325836412027100
- <SYSTEM32>\calc.exe
- %PROGRAM_FILES%\DelSvel.bat
- %TEMP%\WERf24b.dir00\calc.exe.mdmp
- %PROGRAM_FILES%\qq.exe
- <SYSTEM32>\_qq.exe
- <SYSTEM32>\_qq.exe
- %PROGRAM_FILES%\qq.exe
- DNS ASK 32###.go3.icpcn.com
- ClassName: 'TRE1001HS' WindowName: ''
- ClassName: 'MS_WINHELP' WindowName: ''