Technical Information
- [<HKLM>\SOFTWARE\Classes\lnkfile\shell\open\command] '' = '"%PROGRAM_FILES%\Tencent\QQ\Bin\TXOC.exe" "%1"'
- %PROGRAM_FILES%\TTPlayer\TPlayer.exe
- %WINDIR%\regedit.exe /s "%TEMP%\6QO79.reg"
- <SYSTEM32>\wscript.exe "%TEMP%\D0JI4.vbs"
- %TEMP%\6QO79.reg
- %TEMP%\D0JI4.vbs
- %PROGRAM_FILES%\TTPlayer\Config.ini
- %PROGRAM_FILES%\TTPlayer\TPlayer.exe
- <SYSTEM32>\Factory.dll
- %PROGRAM_FILES%\Tencent\QQ\Bin\TXOC.exe
- %PROGRAM_FILES%\TTPlayer\TPlayer.exe
- 'ip#.#etodo.com':8754
- 'qq#.##aicache.com':8081
- 'ip.##todo.com':8754
- 'pp#.##aicache.com':8081
- DNS ASK ip#.#etodo.com
- DNS ASK qq#.##aicache.com
- DNS ASK ip.##todo.com
- DNS ASK pp#.##aicache.com
- ClassName: 'RegEdit_RegEdit' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''