Техническая информация
- <SYSTEM32>\rundll32.exe ""%TEMP%\ins1.tmp"",ypktwvkxscghwrn install worker
- %TEMP%\ins1.tmp
- 'sl###t.mo.cx':80
- sl###t.mo.cx/ZhdEjYeYt2XdcBPLlZ1I72gSjbkTJBkRkBQ5KjMeA2QP1a7SshbPrtscrxquq8y8SvwubO5q1V8aYFCec4tYWr7K4olLDRHDNgt5AbIDPdY=
- sl###t.mo.cx/atjAlskoTh3O4dTydw3dTzl4TVmjHdRoYdgRKtDfFxXf7iGlgBm9m5lrYTrb7d9GoGnjXFkgsPMfv9IF7xlImhGNf6NrHiAsZfc20JAAjaOPmeAmBafcSXSKZs30WE9xX+JsdvfYzjWYd/TnVRqzg9OhhyEVxO6OJliMoxUod9rj9ovPhb2L+UJJqKXWqElFxhC18RvU
- DNS ASK sl###t.mo.cx
- ClassName: 'Shell_TrayWnd' WindowName: ''