Техническая информация
- <SYSTEM32>\rundll32.exe ""%TEMP%\ins1.tmp"",hwivwnxkd install
- %TEMP%\ins1.tmp
- 'pl###onts.ce.ms':80
- pl###onts.ce.ms/JEPXYdbvwzvUzFQ5bDyCDATURqdjvFMNfdfBnxXt9rKcnafsu5PVqpMszlbPdHsaKfFrk3TQ8yhU+j/HLdmSexgvxk5hMshk7qrGk1YqjVBJ3w==
- pl###onts.ce.ms/lvGJqgCrE5VVGG+M2pviBwtg6dpfFSx3yzR0g7Dr1CiwQSJNFzysdZBYigvdUC+RXJxL9TbpXnxspxzk202vgENxsOfqEBtH2iasWcoh05BZ1gZSQdF8/XcLEVrHcVEVCO3P4fROmh3cv38e//93upnyGjY2jGA5fah2YY3sBlPBDe74GuN5EvJnqwnKL19Bhi9c0+zvCPQ=
- DNS ASK pl###onts.ce.ms
- ClassName: 'Shell_TrayWnd' WindowName: ''