Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'RegistryMonitor1' = '<SYSTEM32>\qtplugin.exe'
- <SYSTEM32>\qtplugin.exe
- %TEMP%\tmp1E3.tmp
- %TEMP%\tmp1E3.tmp
- '89.##9.226.230':80
- 89.##9.226.230/stat1.php
- 89.##9.226.230/stat2.php