Техническая информация
- <SYSTEM32>\rundll32.exe "%TEMP%\ins1.tmp",ozauswrvnug install
- %TEMP%\ins1.tmp
- 'ro###hee.ce.ms':80
- ro###hee.ce.ms/fFvSguZP/4c3+i5a96RwI4a7KIpC6ve+HzvmqdtT0+pzrYQii5FxkQOC1Ve5auDJ+OMVAiG6ulnvGkfjo/0afY9Ik3qdZLGJxHjZQNdF1cvoXw==
- ro###hee.ce.ms/SypuaBYF78qPYwzzeImXY86yptEGisgFP9QxvA1oQkIKqjuotkdBv67bkii4shJMgrE1L8nTJ/BOtPBbxHPY67wXb5wlwz0lGLMExO7wPlfaGS60iEW/H8CBM/ecSK+q3TzuWd0u+px2b1xn0ctLkWXpR2rM/oT2vGISyQkxQHcJqBElSUJkSH8pMbXSez7THu2dUpieeHk=
- DNS ASK ro###hee.ce.ms
- '<IP-адрес в локальной сети>':1035
- ClassName: 'Shell_TrayWnd' WindowName: ''