Техническая информация
- <SYSTEM32>\rundll32.exe "%TEMP%\ins1.tmp",xncujvchq install
- %TEMP%\ins1.tmp
- 'kc###wsko.ce.ms':80
- kc###wsko.ce.ms/Ncyngeikkdjq+JyiC3NfC+3WxaWg8TRg00AQ99j3RiekOxYeoBm7TGmEFMDf1aq4vwRDPZCaDWhORWVwL2sIXwc06spbN2UqWC3xpBPsqIg=
- kc###wsko.ce.ms/HLMCDUmnXP5rReTda0ezTr41eZhrJf/e8pVnU0eb8pe5IKI90HkVV9rGwrUFbjYJdEQCOJwjwUA+en21+nAR65KTgXukpLRdgsEvP3cCKX1ipHBJ5Gk013T0zK3giKvn2i7jLr83Xx+HNxy53KnDg40MC275ywiy9w70ER0IXAckUlrooZYMrEocC32nGtZd9asejH7J
- DNS ASK kc###wsko.ce.ms
- '<IP-адрес в локальной сети>':1035
- ClassName: 'Shell_TrayWnd' WindowName: ''