Техническая информация
- <SYSTEM32>\rundll32.exe ""%TEMP%\ins1.tmp"",kqkpxvobo install
- %TEMP%\ins1.tmp
- 'fo###oer.ce.ms':80
- fo###oer.ce.ms/ANxUnScizkFmmBL53Lv1L8pgeo9jKvBWPN5HWy8en8wiWP/nHQQZvzoYUkdc5VT/LvD8FBdJSd6Q55h4gmi8okNFTln723aOaGzBmu2h8TeGqw==
- fo###oer.ce.ms/aLVPqXxMA38pZi3J42Jbp4zREQICE3gmGtj42FsvwUKaEQ7f0J49gAPy+mMFbixFGntRUdPygPIuyWf3u+3jUeAQC9iOlOvvNmsv7wHeMOazILR1el0hLLPKJq0yUig9D+FiygGEz4+rDzd/TpqgVVNnU4/3CxXHwVGJKPBD9ES5O9REjsQPnOrGJOdzvWUPbO+kB6CP7Yc=
- DNS ASK fo###oer.ce.ms
- ClassName: 'Shell_TrayWnd' WindowName: ''