Техническая информация
- <SYSTEM32>\rundll32.exe "%TEMP%\ins1.tmp",ttreyijrpjflxej install
- %TEMP%\ins1.tmp
- <SYSTEM32>\wbem\Performance\WmiApRpl_new.ini
- 'ko##e.ce.ms':80
- ko##e.ce.ms/nIDkkNEGPBfTQUmXrvhzte/oQp+TlTYoTVQCGgnKQmdBif6WjLRC4SSIedKE2grfAi+Q88fXMplEnm1wKbSmJ6d5iCKQ3dQCK2P98YRKp6ez0g==
- ko##e.ce.ms/IlTjWGEMkIbkPUNf2S0LMfrS/Ss4iVhiIi8h6JJ5Phnl6pmgZG2hgaM29ZJYh1RF2bBIvTuIzZ2GP/p/zO2pVM0UwMbp/e9dgjGowzLbCJ8mqxeVs01yXQQcwAZ3aJXAfeTiH8i83nCm9MfdxPwsur+YRC0IihlM8XYnLgEkHWx8ZHHBtTX5mBn2/RpDirpbQ+2B3G5O9ZQ=
- DNS ASK ko##e.ce.ms
- ClassName: 'Shell_TrayWnd' WindowName: ''