Техническая информация
- <SYSTEM32>\rundll32.exe "%TEMP%\ins1.tmp",kqmryujwnsi install
- %TEMP%\ins1.tmp
- 'mc###l.ce.ms':80
- mc###l.ce.ms/MzUFTNMH7lqgyVR9gLqu8jjsCDhtbTzmhg6FPNTAuJPN4lN4SRGZepm+InKqTOkiX52wyQ3RBhJS7db+KmBZwD+2t1xTl4yyM2GdfL4Tdch7yw==
- mc###l.ce.ms/wKaxPOzxaO0aGoMcrA0o5MwQpMoMGUbti0RcL+EQEZmAzSierH9DXSULDTgIpkrqvgGHontbHNglfbWpWu5Yxi5ulwgVcRAjDjlJZ0vTvYwR1N0k2+wLYe6FO4f6DdSxpinzUgkzDpUAttzfkI/qC1nGoV1D6uq27eNB0Bd4iFl7z4Mq1NKERnuEY72DrizAcCg4F7iRyXw=
- DNS ASK mc###l.ce.ms
- '<IP-адрес в локальной сети>':1035
- ClassName: 'Shell_TrayWnd' WindowName: ''