Техническая информация
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Cheje' = 'rundll32.exe "%LOCALAPPDATA%\mspche.dll",Startup'
- <SYSTEM32>\msiexec.exe
- %TEMP%\nszf6ae.tmp
- %TEMP%\nspf71c.tmp\exerev.exe
- %TEMP%\nspf71c.tmp\1europ.exe
- %TEMP%\nspf71c.tmp\2ic.exe
- %TEMP%\nspf71c.tmp\3e4u - old.exe
- %TEMP%\nspf71c.tmp\6tbp.exe
- %LOCALAPPDATA%\mspche.dll
- %TEMP%\nspf71c.tmp\1europ.exe
- %TEMP%\nspf71c.tmp\2ic.exe
- %TEMP%\nspf71c.tmp\3e4u - old.exe
- %TEMP%\nspf71c.tmp\6tbp.exe
- %TEMP%\nspf71c.tmp\exerev.exe
- DNS ASK 36##uy.com
- DNS ASK ab###tel.com
- ClassName: 'SystemTray_Main' WindowName: ''
- '%TEMP%\nspf71c.tmp\exerev.exe'
- '%TEMP%\nspf71c.tmp\1europ.exe'
- '%TEMP%\nspf71c.tmp\2ic.exe'
- '%TEMP%\nspf71c.tmp\3e4u - old.exe'
- '%TEMP%\nspf71c.tmp\6tbp.exe'
- '%WINDIR%\syswow64\rundll32.exe' "%LOCALAPPDATA%\mspche.dll",Startup
- '%WINDIR%\syswow64\rundll32.exe' "%LOCALAPPDATA%\mspche.dll",iep