Техническая информация
- <SYSTEM32>\rundll32.exe ""%TEMP%\ins1.tmp"",ixmhcrfw install
- %TEMP%\ins1.tmp
- 'jo##e.ce.ms':80
- jo##e.ce.ms/AdLETpbslEQeBW0u3Ff6Q9adEHYaT0NU0a+iRl4hS+PqxlBg3QX3b4haYPJN2QIhf8azCZc8q8rK3NG7mMXZfZ+nJI5k3qh8SFu7TsAfqiMUEw==
- jo##e.ce.ms/eaLowwWVORGe/8qcRtWOVoZWc9rdJOV4Xi9CSViICoQ8GhOIRMF12poUKzIu9MrQL4TXwOM7ev+2Tvwn50+2vN4uzybNuZq/wKknYc77TbW4Xqt2Zm1pcpGaAMPWj9eKUi9vcD8+v0rU9+J26URRGtR4ELiC4Lr9Z4HYSPw5WLsLljqS5Sgb+ZegEWBmJg/41qtzM2hIKi8=
- DNS ASK jo##e.ce.ms
- '<IP-адрес в локальной сети>':1034
- ClassName: 'Shell_TrayWnd' WindowName: ''