Техническая информация
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'QQbuse' = '%ProgramFiles%\Adobe\Explorer.exe'
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'QQbrowrse' = '%ProgramFiles%\idcdps\QQbrowrse.exe'
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'QQbuser' = '%ProgramFiles%\Adobe\Delete.exe'
- скрытых файлов
- %ProgramFiles%\adobe\explorer.exe
- %ProgramFiles%\idcdps\qqbrowrse.exe
- %ProgramFiles%\adobe\delete.exe
- %ProgramFiles%\adobe\explorer.exe
- %ProgramFiles%\idcdps\qqbrowrse.exe
- %ProgramFiles%\adobe\delete.exe
- 'dq##yz.cn':81
- http://www.dq###z.cn:81/exe.php?e=### via dq##yz.cn
- http://www.dq###z.cn:81/ via dq##yz.cn
- DNS ASK dq##yz.cn
- ClassName: 'CabinetWClass' WindowName: ''
- '%ProgramFiles%\idcdps\qqbrowrse.exe'
- '%ProgramFiles%\adobe\explorer.exe'