Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\AppMgmt] 'Start' = '00000002'
- <DRIVERS>\http.sys
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\4TCYZU45\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\W40GYBZ1\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\8G3DW3IH\v[1].jpg
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\9NXIMBOL\desktop.ini
- %TEMP%\101609d.dat
- %TEMP%\100343d.dat
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\8G3DW3IH\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\4TCYZU45\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\9NXIMBOL\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\8G3DW3IH\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\W40GYBZ1\desktop.ini
- '14###.kgkg.net':80
- 14###.kgkg.net/images/v.jpg
- DNS ASK 14###.kgkg.net