Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'ejendomsh' = '%TEMP%\TELE\Spoke2.vbs'
- %WINDIR%\explorer.exe
- %WINDIR%\syswow64\svchost.exe
- spoke2.exe
- %TEMP%\tele\spoke2.exe
- %TEMP%\tele\spoke2.vbs
- %TEMP%\tele\spoke2.exe
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt
- DNS ASK on####ve.live.com
- DNS ASK microsoft.com
- DNS ASK y7####.#m.files.1drv.com
- '%TEMP%\tele\spoke2.exe'
- '%WINDIR%\syswow64\svchost.exe'
- '%WINDIR%\syswow64\cmd.exe' del "%TEMP%\TELE\Spoke2.exe"