Техническая информация
- <SYSTEM32>\rundll32.exe ""%TEMP%\ins1.tmp"",kkcsdsizgpgeobq install
- %TEMP%\ins1.tmp
- 'pr###okmo.ce.ms':80
- pr###okmo.ce.ms/DahipGJbyGZ8PPpL/mRxmYgNNJ4jCngI/3zMilXMLi63k760/gzAh0ZwquNUFiZinkdZtVViOMlvF4JYZFtoz1VdTnu29q/cYvVD2IyKN+08SA==
- pr###okmo.ce.ms/KDTrQUVn6W3SBr/HUJEZrnVZsjs/cxiqII1Ps9MIvXm7b22IVoqTZyFhppUrnPdXXDrhV5RAO9KQ988jN88ZbvgyIhABL7Q6QvOPPNZZYDtDqkg474BqepEu4L8IxggUh4Qs7/0tCu3IMHGHpAxLq4hfu4tQQgbFG7iHf7j41/+hO74ciOktS4q1theKg38Fv2ETdnBkJH0=
- DNS ASK pr###okmo.ce.ms
- ClassName: 'Shell_TrayWnd' WindowName: ''