Техническая информация
- <SYSTEM32>\rundll32.exe ""%TEMP%\ins1.tmp"",yyxgkxpqsidoryr install
- %TEMP%\ins1.tmp
- 'sa###er.co.be':80
- sa###er.co.be/mjHBOkueTeA8GtJPkXHQSt3bBdixlplitTqG6cSkhzxUoQLrbXdGq4/dTcwRDnXT37qXEvqVxvPKu7zafBU82kGPe+av6oIuSg0js/e8TyUPjw==
- sa###er.co.be/GzJkvuxrSnqhuNxia3SsfBeXEp5wMjLM4P/kZ7r865NE6KRsYJVzAaG5wQQrFIT9DS2fiGEEHeD0wMmxHjNpz0Lgpx2/ECCpbludQ+YkgukNXy9nyKBYgR+tjra1csDjFFYMvkR7fGFhZqLYIXhT28fsOLKWPqoxJmGr8F/IbHAR14MPP7oIiHo0o64O1OXHlUEJeGJpFRQ=
- DNS ASK sa###er.co.be
- ClassName: 'Shell_TrayWnd' WindowName: ''