Техническая информация
- <SYSTEM32>\rundll32.exe ""%TEMP%\ins1.tmp"",mxjtizdo install
- %TEMP%\ins1.tmp
- 'sa###ros.ce.ms':80
- sa###ros.ce.ms/YvkELiqgWo3VfBZ5oJ69/SPiJKy9hpwyX5PwrW8a6bbU7hM+zaEVcKqw4gDljYQlwBQiCmTUtLbnACOZVLv/LtNb9pw01iK7RsfGdFAvgpkamg==
- sa###ros.ce.ms/RCmzhsrCriAYqp5yO3DXg2cDpYem0uL2jgTiwLfnACYmxRW6w1VZsnt7D1hkHCIorjrPdKibelmVNLOgTTVrwLWvC+NSgOOy00C5IZLI34Fa1qQh8Du5gspaLwtobReatPVFtOj4u7PKcB1WTzQCohoMHMu0dXPXouTCzE2lrjdDRUvg/sOcbDsJH5Klc5e8xTkA7c9ZOGE=
- DNS ASK sa###ros.ce.ms
- ClassName: 'Shell_TrayWnd' WindowName: ''