Техническая информация
- <SYSTEM32>\rundll32.exe ""%TEMP%\ins1.tmp"",tmkphzsjyryfuw install worker
- %TEMP%\ins1.tmp
- 'se###ls.mo.cx':80
- se###ls.mo.cx/unfJISaV7q/7zNmlBOgkUHkZEX0Q9BuWGnXwCd7b4KM20joIQP/wanIelgxKY005M+VcpkZMSXkDtQdWcTFL7eMotgAtA+p0aZlexptHvYw=
- se###ls.mo.cx/MvRrmXPq/Liox685SF0SHCARSCFN+ISRXod4NiccR0Luy50VHYsvEQus7r+lpmssbZU+zTf3pvPMxfyxN/NMSWGXkxsdwS+HfzWHznYALgsOfcJcur1BmofDquPk8izx+j/ZjqT0+vwYZ9KQOtUPsfUJT2ZhL4WhsJBCB7Vez6Q/bu7aMDIdMdXzTYdoVF/lSmI9isDs
- DNS ASK se###ls.mo.cx
- ClassName: 'Shell_TrayWnd' WindowName: ''