Техническая информация
- <SYSTEM32>\rundll32.exe "%TEMP%\ins1.tmp",xncujvchq install
- %TEMP%\ins1.tmp
- 'kc###wsko.ce.ms':80
- kc###wsko.ce.ms/eHWMHhzrQZ/4wpXkNVxPu0k5SbGFMbmuZRS13DcO9oXPtX/HXAxfXKP/jOShGr1djtQTm/4n1pPxIwODabKHlbJMB67vr8ztQ1hswTQQnp8=
- kc###wsko.ce.ms/zFcfQaiWpfo7cNqDcWNR+QQ28HmKt9bTc+hStbI9/C/pc+wdtdJPuG/eaX7rNYzP3bd1Mlaec0wPaJnF/Na8V0n+zSHYhQNQ8fa6CwID2NLGTPfbVn7Wt1NF25H9TMcjwmJXtUnlZ41hVDBFrUuWM/uJkb5BZYTHgedtHzPrSxwuJVV8sXX8FivkDb4q/ACLJVkpw7jw
- DNS ASK kc###wsko.ce.ms
- '<IP-адрес в локальной сети>':1035
- ClassName: 'Shell_TrayWnd' WindowName: ''