Техническая информация
- <SYSTEM32>\rundll32.exe "%TEMP%\ins1.tmp",rsgafgiwd install
- %TEMP%\ins1.tmp
- 'po###no.ce.ms':80
- po###no.ce.ms/iddBxlmizetIK62MvGJJM+oClHUB72A7S2DIr8SD//gq/tPvcisTB5jwRE5C+Ax09XWQk98fshlxiUQNhSJNVAs3VeJeqdmw7RuKA+gUtOfJrg==
- po###no.ce.ms/YXThyowmL9GJuXq+cJ2GsER1113GtCrjilYshv469XVhPqHkpJUArTRiL0n/xKOta4rsPtdQrSzkhTfMWekK3ZvuYeMojdA2YkEi7LvFwoikoZJAFszEm9Hl+Mv2WOv/EEscrgO/V4eQk9iKvBCDFK5V5MiV4mbGT5m0Ter04M/kkJgRualYbzPV6+gul8aff+b0zc15gMc=
- DNS ASK po###no.ce.ms
- '<IP-адрес в локальной сети>':1036
- ClassName: 'Shell_TrayWnd' WindowName: ''