Техническая информация
- <SYSTEM32>\rundll32.exe "%TEMP%\ins1.tmp",qwhmeowaq install
- %TEMP%\ins1.tmp
- 'po###o.cz.cc':80
- po###o.cz.cc/ZTtezrks3iVP5CaaVDHNp/Sdz7FQ1vJSDj7YVcK3BngR2yTqp7uOTCbg2gu0KL3MtZEmyEuzjp/sz5qneyYDGCVziQgw+8t7+cnRZu0FtkQi+g==
- po###o.cz.cc/RwhyqLHvkGmd9HeuwPPnxxDlZmlpa5zzqO+jicEcI5IuT1YrF+Npgdok31rkUwGMwYMG03sUakITA2HVurVVyPqWo1XElDGFgxVAL5xlG41uIYKs4chKrq5OIM4YnoiGYoqZRZct93ZkBYiqpb1+gplY0smkGaKfTOG2fKrwLrLJa0QiDlnPnOP2T9AvH5xp28mNLov257Y=
- DNS ASK po###o.cz.cc
- '<IP-адрес в локальной сети>':1036
- ClassName: 'Shell_TrayWnd' WindowName: ''