Техническая информация
- <SYSTEM32>\rundll32.exe ""%TEMP%\ins1.tmp"",kqmryujwnsi install
- %TEMP%\ins1.tmp
- 'sa###zo.ce.ms':80
- sa###zo.ce.ms/odXIfquiU5zudRudW4Jvc95ViVOW/x6/CQ5u7ljxr2ohywEX2vVjaCIEtgeCQMl+kfgHnExHJ6e2vUwBMjpySiJO/jBMMgtKx28c+cTjMoPq3A==
- sa###zo.ce.ms/vdswzjtPfuu5GWL0C8wbMMro3qSHWmr1OIqz1dpAwR9rAQ6Fn2zPKdvesJEQzW3mNzqAZikuXP4cDNl+2JnNroILbXY5hwDRJsaU5X4xmRXJRJ6mRW+DamBFWuuUUImhX7VnMF2ua7Ggj4XVpUHchGAP68ZAkOpHbIFmNE4MyIE0iojORyOPJdB8JxR65j76hc03v0iD6tY=
- DNS ASK sa###zo.ce.ms
- ClassName: 'Shell_TrayWnd' WindowName: ''