Техническая информация
- <SYSTEM32>\rundll32.exe "%TEMP%\ins1.tmp",rsgafgiwd install
- %TEMP%\ins1.tmp
- 'cl###n.ce.ms':80
- cl###n.ce.ms/swelHwNA1kVz6iUvujsLdKr/MYjLpnlKyv7VfeNruKysK/Y0LVj7vlhSNdh1aqCgpCa963mhLPj1Dnsfh2hH22id1J2yhskOENx1iqx5XKPQ0A==
- cl###n.ce.ms/KXKnKkav+3O95dtTJmK0wXenUKG8IUKNbLflhVbEtmbelLfxpVf+mfkIzxspc//FEtVr0i5VkST3UlNUMhvl9Q6YQezrZcCiZYVCObQhwo1T1kXqARCH7EpXnaQIARxGymyTypAgG3FHN7wnVSnlRudQGc8W4mG+B75gqGxrceoxlJBySSxEimdW6RIzQ/fEJKCTigRDNXk=
- DNS ASK cl###n.ce.ms
- ClassName: 'Shell_TrayWnd' WindowName: ''