Техническая информация
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\] 'MSSMSGS' = 'rundll32.exe winvwc32.rom,RLIVtw'
- iexplore.exe
- %TEMP%\fmr37d1.tmp
- %WINDIR%\syswow64\winvwc32.rom
- %TEMP%\fmr37d1.bat
- %TEMP%\fmr37d1.tmp
- 'co##############e-chains.prod.autograph.services.mozaws.net':443
- DNS ASK sa###oft.net
- DNS ASK co##############e-chains.prod.autograph.services.mozaws.net
- ClassName: 'IEFrame' WindowName: ''
- '%WINDIR%\syswow64\cmd.exe' /c "%TEMP%\FMR37D1.bat" (со скрытым окном)