Техническая информация
- %TEMP%\nbbrppa.ajhnvyaumf
- %TEMP%\qrzmeq.txt
- http://ad#.#ensa.at/api1/nxi3tigtuEL_2Fp/cMphI8S7oAzXMQ4uT9/KDWjkuqfS/zP3bVaUQLqRQBh7vB5XQ/y4dJU5F7Em8uZTAJ4w7/6xuskz6omWBBE8fm1g8t6D/CkyPsUovPwaXB/Cf_2F1pf/mVobCYA6lgGbE4l_2BZZjQe/LMkmXVlA5m/H...
- http://no##.calag.at/api1/7wjKHpbfVxm7jRVkT4W_/2B60RaGUcT2DY2p7Fmd/ciYZBkFOMDybipCKgm_2Fb/_2F6ryQbTbsdI/_2B7JxA_/2BG_2FUkc8uEae2awrdOhfD/_2FyXa9at7/oeBlFZcBok3YUSAev/gvt3Eg2tiTt_/2Bh4Zoj2DTl/UW...
- DNS ASK ad#.#ensa.at
- DNS ASK no##.calag.at
- ClassName: 'Static' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- '<SYSTEM32>\regsvr32.exe' -s %TEMP%\\qrzmeQ.txt