Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'QQvb' = '%CommonProgramFiles%\System\QQBe5R.exe'
- %CommonProgramFiles%\System\QQBe5R.exe
- <SYSTEM32>\ping.exe -n 2 127.0.0.1
- ecmd.exe
- 360tray.exe
- %CommonProgramFiles%\System\admin.obj
- C:\RCX1.tmp
- %CommonProgramFiles%\System\htrn_jis.dll
- %CommonProgramFiles%\System\htrn_jis.tmp
- %CommonProgramFiles%\System\QQBe5R.exebnb
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\count[1].asp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\sms[1].jpg
- %CommonProgramFiles%\System\admin.obj
- %CommonProgramFiles%\System\htrn_jis.tmp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\count[1].asp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\sms[1].jpg
- '88##99.com':80
- 88##99.com/sms/sms.jpg
- 88##99.com/count/count.asp?cm###
- DNS ASK 88##99.com
- ClassName: 'ToolbarWindow32' WindowName: ''
- ClassName: 'ReBarWindow32' WindowName: ''
- ClassName: 'MSTaskSwWClass' WindowName: ''
- ClassName: 'SysPager' WindowName: ''
- ClassName: '' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'TrayNotifyWnd' WindowName: ''