Техническая информация
- <SYSTEM32>\rundll32.exe ""%TEMP%\ins1.tmp"",ycjlhqoftunp install
- %TEMP%\ins1.tmp
- 'sh####eroe.mo.cx':80
- sh####eroe.mo.cx/LNERoIDOxOVNx0bRIXchA51AoazS1W7VDqo+JqB/b/COkSki4GDkj8SSQB6AixdO0UyoAmOG8/XgwIYtA19Pzq66TCv8W2pRQdaS9sVNg2s=
- sh####eroe.mo.cx/dfpLVasqVTWTQSeD1tN2iOIk9AYY+Gmiab/VM3LQHr6iKkrA0sxpv5NHWKXT/gxtmiYHdPlomGw8tf0wktwQZ6LGibs0Kg91RBtPWREggzLvI6CBG1RAlRDi4JTjzHYOSlEAdFA696Z+jPWeuwR2ijTqXEcfewchntVRb3WCasKJJlOau4+65A8bjVYZ7ktCu3dIBBtO
- DNS ASK sh####eroe.mo.cx
- ClassName: 'Shell_TrayWnd' WindowName: ''