Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\RemoteAccess] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\1Rootkit] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\2Rootkit] 'Start' = '00000001'
- <SYSTEM32>\ping.exe localhost -n 1
- <SYSTEM32>\svchost.exe -k netsvcs
- <SYSTEM32>\sb.dll
- <DRIVERS>\Test_Rootkit.sys
- 'yj##.3322.org':20090
- DNS ASK yj##.3322.org