Техническая информация
- <SYSTEM32>\rundll32.exe ""%TEMP%\ins1.tmp"",hwivwnxkd install
- %TEMP%\ins1.tmp
- 'ly##n.ce.ms':80
- ly##n.ce.ms/hSqQnfgxXSxcnlgWiX2FBhJOe2PeR+SsCkdTpGdWiHTHvE8bSmVnHS4pyz/UUovNvXzrhzmdKO/z+XCDIKFmZiV9t61H+UmUhTDdgTObYY9VTw==
- ly##n.ce.ms/TKsyQgBMFouBzpCocVcra42SPIDQ+yCnRGWv23RrN/nlZvtgioYrKjAneMaGwVtRZZmaEdTiunWbTSC2DrfauPcMQ6bzP+Wc/FBnX7sEBE/fUNrhus0bf8qFd78Q/mHG07gV8tN3zGA4whOxbTEpdgcnbuUkZMhCLOAv7Nt9gEOZToSczhr3zbemym7Ebwlclx4b9Qs8NxM=
- DNS ASK ly##n.ce.ms
- ClassName: 'Shell_TrayWnd' WindowName: ''