Техническая информация
- <SYSTEM32>\rundll32.exe "%TEMP%\ins1.tmp",zbgllwvjaeep install
- %TEMP%\ins1.tmp
- 'ho###n.ce.ms':80
- ho###n.ce.ms/fYMGwnMXMIox6w3wL5jfgMeJN99wlSG3QMeFXqUw7DEUbTLlUtlIIbg3hWi4Ylj8rwN+kdAu+ZGJtmqgTvRM8WqunUJcRphxxNhhJK5+pJtmng==
- ho###n.ce.ms/ZmZGbbTlB9OMOvvZ0sO6Z9vn6gJzLsySS0Fvn0uWGErPZXKMkaJqUk4/x09tFoOWx6sPAx4zALGSd7UUdi7B05XoNGFwwluRlajHd/wXaKI77Wz6u+/BbHrnkRLaukVTMxgPQxtqYv/WZNVDhuTNUCm0H2/BUEADUQ2NuX+SRMlPg91l1Jcs1ReGzkdDutalXaFgAiNJUx4=
- DNS ASK ho###n.ce.ms
- '<IP-адрес в локальной сети>':1035
- ClassName: 'Shell_TrayWnd' WindowName: ''