Technical Information
- '<SYSTEM32>\rundll32.exe' %PROGRAMDATA%\ieTneVi.dll,DllRegisterServer
- %PROGRAMDATA%\ietnevi.dll
- http://ma###262020.com/files/april8.dll
- DNS ASK ma###262020.com
- '<SYSTEM32>\rundll32.exe' %PROGRAMDATA%\ieTneVi.dll,DllRegisterServer' (with hidden window)
- '%WINDIR%\syswow64\msiexec.exe'