Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'WindowsUpdate' = '<SYSTEM32>\WindowsUpdate.exe'
- %TEMP%\nsq3.tmp\NSISdl.dll
- <Текущая директория>\setuprun.exe
- %TEMP%\nsb2.tmp
- %TEMP%\nsq3.tmp\System.dll
- 'fi##.#qhelper.com':80
- fi##.#qhelper.com/bindsoft/bindsetup.exe
- DNS ASK fi##.#qhelper.com