Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\6to4] 'Start' = '00000002'
- C:\Del1.tmp -delself 164 "<Полный путь к вирусу>"
- %WINDIR%\Temp\~tmp283c4c16.old
- C:\Del1.tmp
- <SYSTEM32>\win32sp2.dll
- 'su#####s1.serveblog.net':443
- DNS ASK ns#.#322.net
- DNS ASK su#####s1.serveblog.net
- DNS ASK ns#.#hina.com