Техническая информация
- <SYSTEM32>\rundll32.exe "%TEMP%\ins1.tmp",gugsaxfq install
- %TEMP%\ins1.tmp
- 'cr##.ce.ms':80
- cr##.ce.ms/hsTmmIMcgMmmu1dQMxG71UFTAaWWOwrx/p4JO+34sc1AtNUiy29Rv/TqvCp7hGCf28tzXn0W3vdFMIHy1XqnW7EaGNahPhaAncqcBTfbNOE=
- cr##.ce.ms/vYelsUQF1zjVGpN9vw5m/FvHNoiu4trCdq92rmZHY3kITYW5gQyZtkQ1ezEOVTtmyXD3rChN7IBvMbQBfGYOgjM587NrDxswWpVgZoaIRqVMsOkhnCAaabt27yTP8N3MxfsZM8AFdoGJTn9neA1QYRGp/tFvuuC8LSXZ4fNVx4BkAzhUiz59y0DsJTk8fU2tW9qMNFeR
- DNS ASK cr##.ce.ms
- '<IP-адрес в локальной сети>':1036
- ClassName: 'Shell_TrayWnd' WindowName: ''