Техническая информация
- <SYSTEM32>\rundll32.exe ""%TEMP%\ins1.tmp"",yyxgkxpqsidoryr install
- %TEMP%\ins1.tmp
- 'fo###erg.co.be':80
- fo###erg.co.be/GMrMGTuorw+jNNiX8SDqc+Qi6p0m2Sj/A2GMQ6U5rV2oPhfjEp/26f9MlA3EGaEYerxSgSwxnQjDXAJNSj3WNHX6Yla0E4+J46K7hRIO/1vUmQ==
- fo###erg.co.be/zyJWVJTRYtscmKyS/7ftGxxS23e7s1dO0tU4iSWGsSVYqsr3AUsg+R86lnGVr0EKRTZQWIAaxi+CdYBk4Z7u4d7E7N//+51oYY4y/j9IrHix0GBYfM9U/iQAwWW3Ryrey5GZz2/ryZhE1l9PcxBLY6ha8Q4eo9dagUOGxdmtum8uHTLE3ijM4c3X9T+DaOiNAMC+8w7eYjI=
- DNS ASK fo###erg.co.be
- ClassName: 'Shell_TrayWnd' WindowName: ''