Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'QQExternal.exe' = '<SYSTEM32>\QQExternal.exe'
- <SYSTEM32>\QQExternal.exe
- <DRIVERS>\etc\hosts.ics
- <DRIVERS>\etc\hosts.dz
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\tj[1].htm
- 'localhost':1037
- 'localhost':1039
- 'yz.##ltsf.com':80
- http://yz.##ltsf.com/tj.htm
- http://yz.##ltsf.com/host.txt
- DNS ASK yz.##ltsf.com
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- '<SYSTEM32>\QQExternal.exe'