Техническая информация
- <SYSTEM32>\rundll32.exe ""%TEMP%\ins1.tmp"",lspjjmlaeodyad install
- %TEMP%\ins1.tmp
- 'cl###oer.cz.cc':80
- cl###oer.cz.cc/ZlEyWjIvzcDulgdSQ/O6D2r2q2Si3x5DAAHCiqMt4vMHWUNCZ6n/ATFc5sS9Cy6rbC1BJ79I1bPKHfp4C4GSx4oHQyF9lx5nA/If22MnwZVMxg==
- cl###oer.cz.cc/ddBlOviDWhoSyXQ0zdSljGYUclSmmq5eJUxMT6470PWWZRm7XgtMctIaeTvSIoYbxJkeJ0r7CIGLJLfnaSZN4eui8Zg0vOCJedevEnutj002MOl7CWPrjYUKA2rMYk7GZw9ZF5Xt1xnFgjX4xtlFNscSREclUx8goCU1gmBAvGOHylPwJ2zotwQ1DqWSSnmyRLGRFf5lwHg=
- DNS ASK cl###oer.cz.cc
- ClassName: 'Shell_TrayWnd' WindowName: ''