Техническая информация
- <SYSTEM32>\rundll32.exe ""%TEMP%\ins1.tmp"",zpjtqydvhswu install worker
- %TEMP%\ins1.tmp
- 'lo###on.ce.ms':80
- lo###on.ce.ms/ghfsoHJXG9TuR2I7Z23XZWfqsL/6UQuVqVme0pbeKMdk370emM/jT+z90hB+yqB53MXXBYP1zs1c4JKMxvOnphtDH4wV0wetIIBvfdB6zXQ=
- lo###on.ce.ms/YAFNMMcbzPTFuNu+a9AjawPhcGKUCHA4BbhAfzKd1/q+qFlip2+G2HYuQfu9lLm1KuGSOcr6/j3QsFJxS0vSQZFfaphkEmY34tDw/9fc3tMPPPHRY2a6fVAbC+ADD8kKAhOjpJ21mMEUjRhIqEqm2vsqjKleNtynAb+WaguwJI/ZSzFS/asuNwYKkObRwipW0NCkTdJj
- DNS ASK lo###on.ce.ms
- '<IP-адрес в локальной сети>':1035
- ClassName: 'Shell_TrayWnd' WindowName: ''