Техническая информация
- <SYSTEM32>\rundll32.exe "%TEMP%\ins1.tmp",knzlvyxp install
- %TEMP%\ins1.tmp
- 'ge###re.cz.cc':80
- ge###re.cz.cc/bFWkldbaPwMXpLjIkSRVtxOyHuocEdBiWtt+rgt/OuTWMmUxYoTD4Fp6/jU/F+ALvrYnwvUo7oJoImutZqACCCBkr5akBD1bsaQsGwhAep9xUg==
- ge###re.cz.cc/zbnJlUcbw52oEj+DyhDaVz4DdowaLZMW5Pn2fUfoAUA4jlj47SO3n6slZxU2mRgxrSZxZzGEYzamuFx7iGLF+eZGiDC4b14gjA5uRSjUbcvoNsEetE5iEVJVRZ1RejX1ThDzWZFmdMSgdOSKOjKxeApPUGPJR7sd50Ll8I/upFKMxNRQQ03c6BycGDZQaqvokFruMsNDK/8=
- DNS ASK ge###re.cz.cc
- '<IP-адрес в локальной сети>':1035
- ClassName: 'Shell_TrayWnd' WindowName: ''