Техническая информация
- <SYSTEM32>\svchost.exe
- <SYSTEM32>\lsass.exe
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\PU064NVX\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\A7IR4F0B\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\KPQNOLUV\desktop.ini
- %TEMP%\139d2e78
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\E9MJ4L6B\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\A7IR4F0B\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\KPQNOLUV\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\E9MJ4L6B\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\PU064NVX\desktop.ini
- %TEMP%\139d2e78
- 're###lerta.com':80
- re###lerta.com/yueoamdf.php?dm##
- DNS ASK re###lerta.com
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'