Техническая информация
- <SYSTEM32>\rundll32.exe ""%TEMP%\ins1.tmp"",kqmryujwnsi install
- %TEMP%\ins1.tmp
- 'me##d.ce.ms':80
- me##d.ce.ms/QhckHNxvm/uCZEVkOKclSoYmCnNCxJEZD/u1dK0c019EtzhMtLp8mg7gSPutSTYPRQpaPu+t24pPDhFNRip9G1Xoc1CBSk700OCz42D3EZgdSA==
- me##d.ce.ms/FeHUIfYp5nO8yhh3xzqCoxxnsS29WZ72eD6nxr7DmFzKLUbVRdFLfD+JNk/a4XBGPv1q4knEGgRXMDmFcIImE31AQMPeT5xdqJJhP3nMg9RIfQxz7EI+CLSv0I/OsLOe5pmHCnO4DANSh3Hp62zPjM98BNpEshMbIH0X1WRQfjBRVJovaBUCuEbxYq+zJcjlAQbtzLwiCAA=
- DNS ASK me##d.ce.ms
- ClassName: 'Shell_TrayWnd' WindowName: ''