Техническая информация
- <SYSTEM32>\rundll32.exe ""%TEMP%\ins1.tmp"",zubwdnzeg install worker
- %TEMP%\ins1.tmp
- 'lo###ss.cz.cc':80
- lo###ss.cz.cc/IfTltVUvD4wOf1Q+Zm7Yud2nS+eoNABez0B/JsXD45eJ1wtPbFTeFlI6ise7VPikME39ulHb/FwBfruyjcr29jyqv2V/Y1NCDr00HJaDxX5Ocw==
- lo###ss.cz.cc/ToJDeWAB5EyFdNcLLUk1rtCKXoh0oV6kh5wQlg//2PqEZi+8FlU22R0Dh30WJhM5AZpEo7YM51LcQAYxWtQ1NvgxrUcy6c6/zjbv0lmVn9zTwbW4A0o9G/am/966hYNfEAB5WhFt4YLoOg6QsKpIjZ0sNPDMyw/jyrNaKXP27nn1YkRQA/0ajS8E2dSPekm5zBLbQxaETpU=
- DNS ASK lo###ss.cz.cc
- ClassName: 'Shell_TrayWnd' WindowName: ''