Техническая информация
- <SYSTEM32>\rundll32.exe ""%TEMP%\ins1.tmp"",wqrszmdkjz install worker
- %TEMP%\ins1.tmp
- 'es###e.mo.cx':80
- es###e.mo.cx/PEftQaYRYD6h6R95dp1Md/dN/oXzcIkSF20+ElPE8B2GcDGkxTNasGw8IB5YjxB1L3Rce6RDIbCWQJ47El/G3xtSk27+RUSHACmOrAEtj8U=
- es###e.mo.cx/LgcoDGBuuwjO4LzE6b7qhnYCZ/35aRWXtIIFpxOlIhswsdsJFuWdVfn6NxGg6bgDC3MTYysRRyA5foduvuBC0ZFHI/+A/iW2tJcuPy5ulaxmiGp5tlQCkOGy/ZmV2SovutLN7l7KtB+wr8znZqEXbjPszdFTRA47sg2qPN5wFpZW6smnnBbdnxyqWtc7xyV+IWGnOnmz
- DNS ASK es###e.mo.cx
- ClassName: 'Shell_TrayWnd' WindowName: ''