Техническая информация
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\] 'MSSMSGS' = 'rundll32.exe windco32.rom,rPMfAyshK'
- iexplore.exe
- %TEMP%\ejia62d.exe
- %TEMP%\gfrb29c.tmp
- %TEMP%\ejib1b3.exe
- %WINDIR%\syswow64\windco32.rom
- %TEMP%\gfrb29c.bat
- %TEMP%\gfrb29c.tmp
- %TEMP%\ejib1b3.exe в %TEMP%\fd52.tmp
- DNS ASK ob####fseher.net
- DNS ASK li###6b0.com
- ClassName: 'IEFrame' WindowName: ''
- ClassName: 'PROGMAN' WindowName: ''
- '%TEMP%\ejia62d.exe'
- '%TEMP%\ejib1b3.exe'
- '%WINDIR%\syswow64\cmd.exe' /c "%TEMP%\gfrB29C.bat" (со скрытым окном)