Техническая информация
- %ALLUSERSPROFILE%\Start Menu\Programs\Startup\Xy.exe
- '<SYSTEM32>\QQExternay.exe'
- '<SYSTEM32>\services.exe'
- <SYSTEM32>\services.exe
- <SYSTEM32>\QQExternay.exe
- 'qi###.f3322.org':8000
- 'b.###ne.qq.com':80
- b.###ne.qq.com/cgi-bin/blognew/blog_output_data?ui#############################
- DNS ASK qi###.f3322.org
- DNS ASK b.###ne.qq.com
- ClassName: 'WTWindow' WindowName: '(null)'
- ClassName: 'TForm1' WindowName: '(null)'
- ClassName: '(null)' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'