Техническая информация
- <SYSTEM32>\rundll32.exe ""%TEMP%\ins1.tmp"",gugsaxfq install
- %TEMP%\ins1.tmp
- 'ro###no.ce.ms':80
- ro###no.ce.ms/QGHiTwPmEm5x8y+uGnKjCKrGRVOIu0IiMfzJjluedSLcLQZaFd4s5+FFDiRSVdI1f/dGwI6jqyFPxoCfQknu+3j6jV2I6lLdr19mnF1/t8c43g==
- ro###no.ce.ms/pDWnSLkHdLhQr1b43+RmBz02AaMKNW1uXbc0HahBBg9XCP+vjz5wDukvpAb0sNWCDpQ2LvtI4X15kFjhOOSv6Y1tHYIjBiA5eOezwfKQdIapJNRtAeU9gdV/VlG73ovp57Uc7BDVh+jU3jZ6VmcSBFkDI+jGiAfhKsoJ7r+CYFfGIW3j1dvcJE1TG86+AU2NVdkx/1sWwr4=
- DNS ASK ro###no.ce.ms
- ClassName: 'Shell_TrayWnd' WindowName: ''