Техническая информация
- <SYSTEM32>\rundll32.exe ""%TEMP%\ins1.tmp"",joauztdcbqsj install
- %TEMP%\ins1.tmp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\0D6B6PI5\8wP3NFQ92xEnRPpx5jHT5z935vOC3GofWnmbg==[1]
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\OezSCcrQ4V9WCLbhusg80HjoIOz6+CXhjZBjbl998C08vSDJxVKV2+6so9lENTuAzLfsVNh66ZQDKc+8BoNIIws6HNAYSUgxtA7hX316yY2rAwrjslbg6FVdMJyWsUxarh7k4J1HNeL7rpokBrvXa[1]
- 'op##.co.be':80
- 'localhost':1035
- op##.co.be/yHPpQSSClgpyhPr0dd6s4uQl+cQGg5hLftSFTIv03xsmZMIwGaKiefcsiOnvyLukNxPu8GET/8wP3NFQ92xEnRPpx5jHT5z935vOC3GofWnmbg==
- op##.co.be/OezSCcrQ4V9WCLbhusg80HjoIOz6+CXhjZBjbl998C08vSDJxVKV2+6so9lENTuAzLfsVNh66ZQDKc+8BoNIIws6HNAYSUgxtA7hX316yY2rAwrjslbg6FVdMJyWsUxarh7k4J1HNeL7rpokBrvXaqVEyIqrxtckWVatb+dWwTvOajpf42+NHULT9oPZf+apH0sOF1Q471M=
- DNS ASK op##.co.be
- ClassName: 'Shell_TrayWnd' WindowName: ''