Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\WYadgijl] 'Start' = '00000002'
- '%CommonProgramFiles%\Microsoft Shared\MSInfo\QQProtect.exe'
- '%WINDIR%\№эјмІвЗэ¶ЇіМРтV1.0.exe'
- C:\80.txt
- %CommonProgramFiles%\Microsoft Shared\MSInfo\QQProtect.exe
- %WINDIR%\№эјмІвЗэ¶ЇіМРтV1.0.exe
- %CommonProgramFiles%\Microsoft Shared\MSInfo\QQProtect.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\api[1].htm
- %CommonProgramFiles%\Microsoft Shared\MSInfo\QQProtect.exe
- %WINDIR%\№эјмІвЗэ¶ЇіМРтV1.0.exe
- 'yu##.f3322.org':8010
- '11#.#9.19.24':80
- 11#.#9.19.24/api.php
- DNS ASK yu##.f3322.org
- DNS ASK .#.
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'MS_WINHELP' WindowName: ''