Техническая информация
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Fmeredugug' = 'rundll32.exe "%LOCALAPPDATA%\mvete3.dll",Startup'
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\] '1806' = '00000000'
- %TEMP%\nsy1c19.tmp
- %TEMP%\nsd1c39.tmp\cb.exe
- %TEMP%\nsd1c39.tmp\1europ.exe
- %TEMP%\nsd1c39.tmp\2ic.exe
- %TEMP%\nsd1c39.tmp\3e4u - old.exe
- %TEMP%\nsd1c39.tmp\6tbp.exe
- %LOCALAPPDATA%\mvete3.dll
- %TEMP%\nsd1c39.tmp\1europ.exe
- %TEMP%\nsd1c39.tmp\2ic.exe
- %TEMP%\nsd1c39.tmp\3e4u - old.exe
- %TEMP%\nsd1c39.tmp\6tbp.exe
- %TEMP%\nsd1c39.tmp\cb.exe
- %TEMP%\nsd1c39.tmp\2ic.exe в %TEMP%\33fc.tmp
- DNS ASK w3###ools.com
- DNS ASK ab###tel.com
- DNS ASK li##ro.it
- DNS ASK wi#####smortgages.in
- DNS ASK we##atum.in
- ClassName: 'SystemTray_Main' WindowName: ''
- '%TEMP%\nsd1c39.tmp\cb.exe'
- '%TEMP%\nsd1c39.tmp\1europ.exe'
- '%TEMP%\nsd1c39.tmp\2ic.exe'
- '%TEMP%\nsd1c39.tmp\3e4u - old.exe'
- '%TEMP%\nsd1c39.tmp\6tbp.exe'
- '%WINDIR%\syswow64\rundll32.exe' "%LOCALAPPDATA%\mvete3.dll",Startup
- '%WINDIR%\syswow64\rundll32.exe' "%LOCALAPPDATA%\mvete3.dll",iep