Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\6to4\Parameters] 'ServiceDll' = '<SYSTEM32>\at.dll'
- [<HKLM>\SYSTEM\ControlSet001\Services\6to4] 'ImagePath' = '<SYSTEM32>\svchost.exe -k netsvcs'
- [<HKLM>\SYSTEM\ControlSet001\Services\6to4] 'Start' = '00000002'
- '<SYSTEM32>\cmd.exe' /c del "<Полный путь к вирусу>" > nul
- %WINDIR%\Temp\~tmp291f2512.old
- <SYSTEM32>\at.dll
- 'ne#.#zxcode.com':443
- DNS ASK ns#.#322.net
- DNS ASK ne#.#zxcode.com
- DNS ASK ns#.#hina.com