Техническая информация
- <SYSTEM32>\rundll32.exe ""%TEMP%\ins1.tmp"",tntkdisomhb install worker
- %TEMP%\ins1.tmp
- 'hm###s.ce.ms':80
- hm###s.ce.ms/MsMQnZZImDM4H+MsPjXeVZjnlliOdP7P6lSN4ciTr0T+6wqvvsrcSJQX25Y+Hvldal8WlCtSROWS7MNC6i5zOcVwoLRjNyn6WIV+8Qn4sxw=
- hm###s.ce.ms/HOYsFRpC9EXD8WEs7Qnib5s65q2hUcp1qoX8Kya5J1QUx6nKg3pRWDU2skwqIyj8B5IJ9uHPqGVrsMcFJiLMD1+rvkEh9vw0EN2t8ju3K+dk4qNwAT3mkoXq2lFJT/j4bQLQQQRKOzXloeqb0X0NrqrfMLXWmQJ3BZwlS+5e3iznKgQy8mmXacFase6BNLh0clvrQxvf
- DNS ASK hm###s.ce.ms
- ClassName: 'Shell_TrayWnd' WindowName: ''