Техническая информация
- <SYSTEM32>\rundll32.exe ""%TEMP%\ins1.tmp"",neywywnrbstt install
- %TEMP%\ins1.tmp
- 'cl###or.cz.cc':80
- cl###or.cz.cc/IJjBZXHZyq3FTDyi/apht1gMxYXm4CFtagsQ9wpLav8cY7CC9qcExcR8kMzun01vvONqNKdCcKIo9wkJ3h9Ln7dzIn86Mt0UXIRYJk9QVFpJ/A==
- cl###or.cz.cc/HBoRVXtzYopGXDEFoSorpnYApsvaXCdi2UcelYpcPi90itQx1MVqW0SZzOQLHK+FBnN1mGceHNtEvdsDJeJr7UXGo8kec+8ofSbvxQQLCrfodYbFXev7lER4U5b2BSxK0MzC5IdVtTWB+KU/qXcqRAjSI+d3nzVAh2itmeB1KHHMcliqA3vfAQfHgjORb1Klqk+N2aAk1LI=
- DNS ASK cl###or.cz.cc
- ClassName: 'Shell_TrayWnd' WindowName: ''