Техническая информация
- <SYSTEM32>\rundll32.exe ""%TEMP%\ins1.tmp"",zfubgasokzba install worker
- %TEMP%\ins1.tmp
- 'dc###e.mo.cx':80
- dc###e.mo.cx/rJCXYYWMiQEgntbgKMvoz7GJm9MZLF1CSrDgSHyU9Q1zeopcsJWkT284Zgr7qbSvAjTrN+MGdf7/o0k7jyJpFlt4iu425yPWAhlA+RFyyko=
- dc###e.mo.cx/BkMPpdBe8Oe7zwfA7V0VdpixLpj5wOhHyFS8qIHa1e1kYRaOr33LPplJr9krWtenj0xjolRzMTO4s/2r29rT6cU2xMMbNYUYJFt6tO2qrAEVVkmkcCr8uxmFoj4jXEPpVD96jkL+F8DsYyYPGuRy/WpYDu5ZMejEPtHHgm5tdxg/w5+I+hKyamfefKc5nHNEZTZjDCMv
- DNS ASK dc###e.mo.cx
- ClassName: 'Shell_TrayWnd' WindowName: ''