Техническая информация
- <SYSTEM32>\rundll32.exe ""%TEMP%\ins1.tmp"",yzkszwbw install
- %TEMP%\ins1.tmp
- 'mc###ley.cz.cc':80
- mc###ley.cz.cc/AafLOqlXhg/X94B5mEMHEIm94w7v6bbL8E1Cz3LmX1t1eGED2BSzrhE22RldjTtaVUaeELPP4PBFClzcYyKiR0t9xnogazylI97AUdTyqJfWxA==
- mc###ley.cz.cc/jInkzOSx9yOrVNIdZGrAteu+v5Q3h9zTNiiTu9JVWg4+Z10MQ4DKASoDjNrSVvtHkUh/WP25QKTxxD4OBOGpqSy1b5JGJVyy1z5/wXRBTzKqKUJeZTI1GJhhLAOc/EIwbyoFS6IhGoIwDlWOJ8xQRcBf7+0G1i2cct3PDOHTQdIBOQ0u0+3Y7NyP5tQsKWroRIzSj8r9y/o=
- DNS ASK mc###ley.cz.cc
- ClassName: 'Shell_TrayWnd' WindowName: ''