Техническая информация
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'viyfi' = '%ALLUSERSPROFILE%\pqdcu.exe'
- %ALLUSERSPROFILE%\pqdcu.exe
- %ALLUSERSPROFILE%\pqdcu.exe
- '62.##.226.159':80
- '17#.16.53.7':80
- '<DNS_SERVER>':53
- '%ALLUSERSPROFILE%\pqdcu.exe' /r