Техническая информация
- %WINDIR%\Resources\smss.exe /system
- <SYSTEM32>\rundll32.exe <SYSTEM32>\sysdm.cpl,NoExecuteProcessException %WINDIR%\Resources\smss.exe
- <SYSTEM32>\dumprep.exe 2592 -dm 7 7 %TEMP%\WER727d.dir00\smss.exe.hdmp 16325836412027344
- <SYSTEM32>\dumprep.exe 2592 -dm 7 7 %TEMP%\WER727d.dir00\smss.exe.mdmp 16325836412027324
- %TEMP%\WER727d.dir00\smss.exe.mdmp
- %WINDIR%\Resources\smss.exe
- %TEMP%\WER727d.dir00\smss.exe.hdmp
- %TEMP%\WER727d.dir00\manifest.txt
- %TEMP%\WER727d.dir00\appcompat.txt
- <SYSTEM32>\MSWINSCK.OCX
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\cocoamswinsck.co19[1]
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\cocoadgspy.co19[1]
- <SYSTEM32>\d3dx9_21.dll
- %TEMP%\~DF2F61.tmp
- 'co####gspy.co19.kr':80
- 'co#####winsck.co19.kr':80
- 'localhost':1035
- co####gspy.co19.kr/
- co#####winsck.co19.kr/
- DNS ASK co####gspy.co19.kr
- DNS ASK co#####winsck.co19.kr
- ClassName: 'Shell_TrayWnd' WindowName: ''