Техническая информация
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'HQIDLp.exe' = '%ProgramFiles(x86)%\HQIDLp.exe'
- '' (загружен из сети Интернет)
- %WINDIR%\syswow64\kabaurl.dll
- C:\sx.exe
- %WINDIR%\syswow64\kaba.dll
- %ProgramFiles(x86)%\hqidlp.exe
- 'mo##ha.cn':80
- '61.##0.28.140':2017
- DNS ASK mo##ha.cn
- ClassName: 'TAppBuilder' WindowName: ''
- ClassName: 'MS_WINHELP' WindowName: ''
- 'C:\sx.exe'
- '%ProgramFiles(x86)%\hqidlp.exe' -k