Техническая информация
- <SYSTEM32>\rundll32.exe "%TEMP%\ins1.tmp",zbgllwvjaeep install
- %TEMP%\ins1.tmp
- 'gg###on.ce.ms':80
- gg###on.ce.ms/MMypCCtW+WAZJXUGfb1PEhJvcwP07QzhSgAm0BE273aVi1aYKtdyYMiDJAoPH+Vyxj+p0P9JF3+km+iNZ3JmEXB6eUH3mG+/h5SsXPI0LgNGkw==
- gg###on.ce.ms/ibleCLJz8x2qL2wfw3DGFj8vGNM5DHrvCYduyPjZI6y+jX444n/DkAu5Oo5vvx+Pwx/UjziIFKoLDjrrFHwBEXktpP8G4BdF5LzfTfkb7M9j3dlBR1Z5D6eaO3fQfqLm6kXDQ2U3TD8VYu6jQ83DQ7SySwg+vNjAq2/R9F9xqajyZQwQcxAD1z/zuErnzikzAT2GED+APHI=
- DNS ASK gg###on.ce.ms
- '<IP-адрес в локальной сети>':1035
- ClassName: 'Shell_TrayWnd' WindowName: ''