Техническая информация
- <SYSTEM32>\rundll32.exe ""%TEMP%\ins1.tmp"",fzdbpxpsdcrvtd install
- %TEMP%\ins1.tmp
- 'sh####rger.ce.ms':80
- sh####rger.ce.ms/ZTJGyrQYyItBltTj0j6qVPvweGWvkQondRG0Wqr+EZKwwIj2GoR1eYx2oCH5fyQahWq6LNtBx6ZJWZJCY0r1A+Sn+yx4taPG8+ciZsLasstgBQ==
- sh####rger.ce.ms/cOVKHnVHMl+Y6ExAYI1+3jn9rw+fUZZKv0c4dPAoi/kz0x/e9RGfboFLu06MX73i4aXifRHhagHsvF8X4pPE6WAv6v1cSR/cy4oghBJXlBB68b/VRg10FHWthKUqbgxZq9nhIq6MSV0qFg9e32yPnft1k7OAbvSQFQyOF3Rr0ZAf17xoMei7HHoArX7MwsdHYqHnCi+dlIY=
- DNS ASK sh####rger.ce.ms
- ClassName: 'Shell_TrayWnd' WindowName: ''