Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\6to4] 'Start' = '00000002'
- <DRIVERS>\beep.sys with %WINDIR%\Temp\release.tmp
- <SYSTEM32>\dllcache\beep.sys with <SYSTEM32>\dllcache\beep.sys.new
- <DRIVERS>\beep.sys with %TEMP%\release.tmp
- <DRIVERS>\usb20.sys with <DRIVERS>\beep.sys
- %TEMP%\196421_res.tmp
- %WINDIR%\Temp\release.tmp
- %TEMP%\195125_res.tmp
- %TEMP%\release.tmp
- <SYSTEM32>\6to4xp.dll
- %TEMP%\195125_xp.tmp
- <DRIVERS>\beep.sys
- from <DRIVERS>\usb20.sys to <DRIVERS>\beep.sys
- from <DRIVERS>\beep.sys to <DRIVERS>\usb20.sys
- from %TEMP%\196421_res.tmp to <SYSTEM32>\6to4xp.dll
- from %TEMP%\195125_res.tmp to %TEMP%\195125_xp.tmp
- 'xw####8.vicp.net':7900
- DNS ASK xw####8.vicp.net