Техническая информация
- <SYSTEM32>\rundll32.exe "%TEMP%\ins1.tmp",vfajljqyjdqxti install
- %TEMP%\ins1.tmp
- 'ro###ee.co.be':80
- ro###ee.co.be/ujUxkRSf1uO7F56xOz1N3PRkay6iPf3DYS2KPWo0C/73QqGEd7QLcrgm0+nRjnifO5VELsPP/TmQWwAutLbjzda0VGDliuQTOofg6tNKNHEO1g==
- ro###ee.co.be/BOLueYqOlcIDfPlBNemB0jBbGRWLvy4RUtKzQ/jG04NDDeIbhbixsJni1DcYJLovEkFZp8E8wZwp5WQDfCnXQkfZxBy0eiquiKaLCXA5htKRG5t1H+QsnjwPZVCOCwjUrM6mro3r3h86aCx3I7lyVw60STrDYL9iR7gwlMExXaGSrmb1f8CqIk7C8MwwnmsqUCHHv+NgvaQ=
- DNS ASK ro###ee.co.be
- '<IP-адрес в локальной сети>':1036
- ClassName: 'Shell_TrayWnd' WindowName: ''