Техническая информация
- <SYSTEM32>\rundll32.exe "%TEMP%\ins1.tmp",ixmhcrfw install
- %TEMP%\ins1.tmp
- 'wo###ed.ce.ms':80
- wo###ed.ce.ms/lUHtmIgx59QIS9kpFtYAelovI7Kv+KU7U3dy95IgU6L+qVjDNyyxUsULh+JBMgyhEWymnkNA5JovCDFsRM6nrlcVKv91cS9u3FchItgmHjXObA==
- wo###ed.ce.ms/uSOYQJLHChWBatWM3SHKb9sbmMEMgJKF/9znRcr2o8UAbOnm+itptYuVz4grEt7zPQcxKJYqVnHNox3am/MXj5StudLb1l6wBITSQzMAa3UUcw8XGXZ8M2pfXTl2h6t0gD7Omh88mRsrz6J6bYhc8QlLhkrJllT2+ymYefzoAv04d1B7+4/gSvtJdaw+152lSnMRhgtf4io=
- DNS ASK wo###ed.ce.ms
- ClassName: 'Shell_TrayWnd' WindowName: ''