Техническая информация
- <SYSTEM32>\svchost.exe
- <SYSTEM32>\lsass.exe
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\OXAJGLU3\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\XVGPZL14\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\FGHEO234\desktop.ini
- %TEMP%\139d2e78
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\0VZC35C1\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\XVGPZL14\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\FGHEO234\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\0VZC35C1\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\OXAJGLU3\desktop.ini
- %TEMP%\139d2e78
- 'ko###rtot.com':80
- ko###rtot.com/cpskwlde.php?dm##
- DNS ASK ko###rtot.com
- ClassName: 'Shell_TrayWnd' WindowName: ''