Техническая информация
- <SYSTEM32>\rundll32.exe "%TEMP%\ins1.tmp",ixmhcrfw install
- %TEMP%\ins1.tmp
- 'id###a.ce.ms':80
- id###a.ce.ms/VbnUwjnWAsPASqM8WD6N3trZMxCYz2IeKRpcDfsrcQrIifS1GHVyaZkjCBZxLQa2kbL12MZhFpPYycHdyBcR+FDif7k8TMrrCg2LfcggvALhgQ==
- id###a.ce.ms/EPgeNQQr4PpJ6MPqBG0UBLCLra0x6UDJto+DkeOdZW9bpn+LJ9CgxZR/slfdb3m1dLpkzEa6mRlR9vtit7W/QIt9qtdwGIwxzcw4SR0UIcCSIr+0c7rVokE3krR4YyaFi7G3byl4NivoD+WKC8j06yz7ASUkB/e943Yjp8s7UmuRWOuhwoPl8vvyFxkSRj9zKvJBPqArOpE=
- DNS ASK id###a.ce.ms
- '<IP-адрес в локальной сети>':1035
- ClassName: 'Shell_TrayWnd' WindowName: ''