Technical Information
- <SYSTEM32>\rundll32.exe ""%TEMP%\ins1.tmp"",zevhowyuxtullma install worker
- %TEMP%\ins1.tmp
- 'to###all.ce.ms':80
- to###all.ce.ms/iFZEiyXly+gI+ZItdE+X3hLv/OvMGgh8v+cOtU+LXqRXioLnp1r+sb2RA27DQ+7GlbqijzwGcwbWUQpr7yZXRmnsUCs7LhXD+J4BJa00tgc=
- to###all.ce.ms/IDecsKEqpxjKpEBiBDYwCxCZT/UCgRlZWGxqKljuNKhgaKoXLWg/bjpKOYkGfBNlVhw95KLhPRax87PkPL8Gz1o6DNTgvd5iKWL6rNOkCDhYyobO47OWUtYRHNE/SSE1fNo+weJdA0qasvvbq/P/POlJO3Aq+cl8+XS9RmeVHkPUWnfFhyroP957x/o7Lz2OfpJYN26Y
- DNS ASK to###all.ce.ms
- ClassName: 'Shell_TrayWnd' WindowName: ''