Техническая информация
- <SYSTEM32>\svchost.exe
- <SYSTEM32>\lsass.exe
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\G5YNO1YZ\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\IXYLKFAR\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\W05OI7TI\desktop.ini
- %TEMP%\139d2e78
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\U5GTMB0D\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\IXYLKFAR\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\W05OI7TI\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\U5GTMB0D\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\G5YNO1YZ\desktop.ini
- %TEMP%\139d2e78
- 're###lerta.com':80
- re###lerta.com/bsuenwow.php?dm##
- DNS ASK re###lerta.com
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'