Техническая информация
- %WINDIR%\Tasks\SA.DAT
- [<HKLM>\SYSTEM\ControlSet001\Services\6to4] 'Start' = '00000002'
- '<SYSTEM32>\svchost.exe' -k netsvcs
- '<SYSTEM32>\net1.exe' start PDCOMP
- '<SYSTEM32>\net.exe' start PDCOMP
- <SYSTEM32>\svchost.exe
- %WINDIR%\Temp\~tmp4ea872de.old
- %TEMP%\128468_tep.dll
- <SYSTEM32>\OLECL1.dll
- %TEMP%\128468_tep.dll в <SYSTEM32>\privatesys.dll
- DNS ASK ns#.#hina.com