Техническая информация
- <SYSTEM32>\svchost.exe
- <SYSTEM32>\lsass.exe
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\GOMFSJ76\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\XXI74LYV\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\S1URO96V\desktop.ini
- %TEMP%\139d2e78
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\ATABON2N\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\XXI74LYV\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\S1URO96V\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\ATABON2N\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\GOMFSJ76\desktop.ini
- %TEMP%\139d2e78
- 'ko###rtot.com':80
- ko###rtot.com/cpskwlde.php?dm##
- DNS ASK ko###rtot.com
- ClassName: 'Shell_TrayWnd' WindowName: ''