Техническая информация
- <SYSTEM32>\rundll32.exe ""%TEMP%\ins1.tmp"",joauztdcbqsj install
- %TEMP%\ins1.tmp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\0D6B6PI5\erXryRJzLWr1LnCAncnFwF1rS99v0E66THHzTQ952jk9mbeGISRxdGl1RA+dBMqjdRuR7WA3KNVrwxbQjMSrJPtr0kjsm7qOmvlbVwTVbMPwoA==[1]
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\YfXDr1CeYqeNWb1BjAazC9Ks1wv47NM=[1]
- 'ne###onre.co.be':80
- 'localhost':1037
- ne###onre.co.be/erXryRJzLWr1LnCAncnFwF1rS99v0E66THHzTQ952jk9mbeGISRxdGl1RA+dBMqjdRuR7WA3KNVrwxbQjMSrJPtr0kjsm7qOmvlbVwTVbMPwoA==
- ne###onre.co.be/SECQgQQiC+y0eibCxDZ39dslRVfT9DBQFKnVCPx/8700ydotQoErYL3vrafYRTj3fhi/376mEcryWf9C1n8dgvFRAWra5cVKI4ihKPCuHN1hsP8ywRyCOoGWRL+ZqDdjTTEg1xNFrmvaeXRO5gklCYyN8K8zgKsX16s0yLM7VRr/YfXDr1CeYqeNWb1BjAazC9Ks1wv47NM=
- DNS ASK ne###onre.co.be
- ClassName: 'Shell_TrayWnd' WindowName: ''