Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'QQ' = '%CommonProgramFiles%\sochvst.exe'
- %HOMEPATH%\Start Menu\Xnv.url
- %HOMEPATH%\Start Menu\Xnz.url
- <Full path to file>
- from <Full path to file> to %CommonProgramFiles%\sochvst.exe
- '49.#.140.253':2014