Техническая информация
- <SYSTEM32>\rundll32.exe ""%TEMP%\ins1.tmp"",joauztdcbqsj install
- %TEMP%\ins1.tmp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\0D6B6PI5\hXcvcyxg==[1]
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\DCALf3j9QmU=[1]
- 'mo###fre.co.be':80
- 'localhost':1036
- mo###fre.co.be/fwRutcZYl+qQUgk5guDHfNuJu1O85aUwcNPNSTdZFMW0OtGH4NILVmRo4Kfc9p72PMvYuuBIzJic5ELYT+wLYil2OiuefsJcam42z/hXcvcyxg==
- mo###fre.co.be/VqirCGtsAduqAS6U/pfVNvWwG0SuS4OIWyEaGi+JTdMD40Scgh5hwbsSW00aQNcyck9o1eqgcRTwNzDTXjP06Qu06bXi9VIq0e8E25w+vFAaAOaul6T0Ohzu0EH0rsjRD++gQMsn01teFX1FOxmaLtpVhdwsbilI6I4EIp8mXP5WHiS7pU8VvcY6kkH5wnF/DCALf3j9QmU=
- DNS ASK mo###fre.co.be
- ClassName: 'Shell_TrayWnd' WindowName: ''