Техническая информация
- <SYSTEM32>\rundll32.exe ""%TEMP%\ins1.tmp"",hwivwnxkd install
- %TEMP%\ins1.tmp
- 'mo###n.ce.ms':80
- mo###n.ce.ms/sxhwxaBSTx7bpnTMw1bamwjP9AGLzoJE1h5V+1EpeGtbXI41FmrXwlo6QE//QVRDvJG+yR11lpx+2EMJGUi6IdrtVpGqDei7sW+s+723gU+TyA==
- mo###n.ce.ms/zXppJJRrdLHb4RGZQIjhUpjnl3n4ilVedvl4dRtYniYnSC9LPaj2wZIff2zi/i94CU+GjaBCYIdWuiCToSgx3ypOKo/MkSEIwWehPQngPN0lVujGvwY9oNotF+Vp0MJ4kYDqUXquLeHCbhYn91qiJUKjh5FnVpdEpd1ni0PDVn3rBAgj5aBNLlOWO5DhgO5JPZ/ehQSeuLY=
- DNS ASK mo###n.ce.ms
- ClassName: 'Shell_TrayWnd' WindowName: ''