Техническая информация
- <SYSTEM32>\rundll32.exe ""%TEMP%\ins1.tmp"",fzdbpxpsdcrvtd install
- %TEMP%\ins1.tmp
- 'sh####rger.ce.ms':80
- sh####rger.ce.ms/SGmjFTmsWdqDVHZ8oAAVMjlzgvbrKtwTzG5wZGTXdetGjsz0W/N6Gjh3bYI4R+m1E0QWP1jUrzakh2DqV+rGawc3QNzt5n3S0S2y4+IESCPwAg==
- sh####rger.ce.ms/tJeIxiDVdBIL8ULIPgmRaQLPtlhIgFrjOv3kT/acWvHyvMzEO7Krk3Zq2pB3jR359EJsIXaFJjK3glmjNB9Vb2Sy9AKX+ThjZczezJ75jV02VJdaethjq2fk/C69oDbgEudHeAQhaMN4MTg/bl4IdBmf2ZjpGoNQqUmbqefyv8mr37qQKvYiNsETNy/DCB+SSu+ZOyp1PUM=
- DNS ASK sh####rger.ce.ms
- ClassName: 'Shell_TrayWnd' WindowName: ''