Техническая информация
- <SYSTEM32>\rundll32.exe "%TEMP%\ins1.tmp",obonrruaurtkq install
- %TEMP%\ins1.tmp
- 'fo###er.cz.cc':80
- fo###er.cz.cc/zuuDBsNUMZ+A3TQZtyMzBt02SLg1hTqHAJdppmoG0YWukP1nEL9WZns+JvjKnETrPvw4KHg4+u3gDlFU7TyWNnlVp2UbREI1yA8GzYA4f1s=
- fo###er.cz.cc/PSJJxuUvY9BxmrmeB/ctQBrr/OoDdEB2AAgU34HsBGWKZBVRSYfWNEfLCy43RNwfq03PyjSLuiIYKXgW5Mw3dp1qmFs4ec0w1Vr1rBlKdXZMkdZh7uUC0Nd7NHxJaN4hTrfPnENBXHtGURck62NvDoOmZwY3M4wZWVkPZKGolJVoe+SHSe6nrym5ozfSKxQpZZKkNFR2
- DNS ASK fo###er.cz.cc
- '<IP-адрес в локальной сети>':1035
- ClassName: 'Shell_TrayWnd' WindowName: ''