Technical Information
- hidden files
- %HOMEPATH%\desktop\<File name>.lnk
- <Current directory>\ВЅВВєГѕ.exe
- <Current directory>\tqdl\lserver.exe
- <Current directory>\ВЅВВєГѕ.exe
- <Current directory>\tqdl\lserver.exe
- http://www.78###jh.com:88/rxjh.inf via 78##xjh.com
- DNS ASK 78##xjh.com
- '<Current directory>\tqdl\lserver.exe' ABCDE12345dfD58Pj4+dmEyNi9nfDx8TVRreUxqRTJPQzR4TGpJd01BW3xdZDNkM0xqYzRPWEo0YW1ndVkyOXRPamc0fC0+fC1fLU1UWT0=z==