Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\6to4] 'Start' = '00000002'
- %TEMP%\205125.log
- <SYSTEM32>\config\SysEvent.Evt
- <SYSTEM32>\config\SecEvent.Evt
- <SYSTEM32>\config\AppEvent.Evt
- from %TEMP%\205125.log to <SYSTEM32>\kwejw.dll
- 'ap##.3322.org':8000
- DNS ASK ap##.3322.org