Техническая информация
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'ÉÏÍøºËÐÄ·þÎñ' = '%ProgramFiles(x86)%\qqntfo\qqntfo.exe'
- %ProgramFiles(x86)%\qqntfo\qqntfo.exe
- %ProgramFiles(x86)%\qqntfo\bud.dat
- %ProgramFiles(x86)%\qqntfo\bud.dat
- 'ba##u.com':80
- http://www.ba##u.com/
- DNS ASK ba##u.com
- DNS ASK ad####.uenet.info
- ClassName: 'EDIT' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- '%ProgramFiles(x86)%\qqntfo\qqntfo.exe'