Техническая информация
- <SYSTEM32>\rundll32.exe ""%TEMP%\ins1.tmp"",xuuhwnpwaxtu install
- %TEMP%\ins1.tmp
- 'kr###h.co.be':80
- kr###h.co.be/iNYtDujBafspSXBhfKfyBl2KrPpJnwjpRqxyPXccj6UoFS8LRk13L0ZNIHZ81D5uTyd/bzXkwueDgJjIEQNBq9G0TYlbdpC6PbHXiPnKziQ=
- kr###h.co.be/mrTTdVEpeapLZ8uHpxCm/Kw5PxtFZvagrCz+fzPQZhgeqG1NkgVebHTOJRnBO9F1K70Q8pYK6XchUsaXEeoEgPEdAXcqaVZ9ahW/9ysQp4tI9cCUsXJNjyruf5B51UD2JqJvQ/Tunvg5ssYG/AQmHgl/KwAwQjfLbKbDjJTnubXS0f9m/52uxGnwV/KDrFIvbsdoSc/V
- DNS ASK kr###h.co.be
- ClassName: 'Shell_TrayWnd' WindowName: ''