Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\6to4] 'Start' = '00000002'
- %WINDIR%\system\T.exe
- <SYSTEM32>\rundll32.exe %WINDIR%\system\MXSF2.dll,Install
- <SYSTEM32>\regsvr32.exe /s %WINDIR%\system\TaoAPI.dll
- %WINDIR%\system\TaoAPI.dll
- %WINDIR%\Temp\~tmp26b5158e.old
- %WINDIR%\system\T.exe
- %WINDIR%\system\MXSF2.dll
- '14####qaz.3322.org':1982
- 'my###i.8800.org':1982
- DNS ASK 14####qaz.3322.org
- DNS ASK ns#.#322.net
- DNS ASK my###i.8800.org
- DNS ASK ns#.#hina.com
- 'ns#.#322.net':1044
- 'ns#.#322.net':1042
- 'ns#.#hina.com':1036
- '<IP-адрес в локальной сети>':1035
- 'ns#.#hina.com':1038