Technical Information
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'helper' = '<SYSTEM32>\Internat.exe'
- %WINDIR%\explorer.exe
- %WINDIR%\syswow64\internat.exe
- %WINDIR%\syswow64\internat.exe
- 'o.##ec.cn':80
- http://o.##ec.cn/q76174179/fgfd.exe
- DNS ASK o.##ec.cn
- DNS ASK qq##2.net