Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\ISU] 'Start' = '00000002'
- '%PROGRAM_FILES%\isu\isus.exe'
- '%PROGRAM_FILES%\isu\isus.exe' "-i" "isu_red" "isu_red03"
- %PROGRAM_FILES%\isu\isu.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\isu[1].exe
- %HOMEPATH%\DesktopАОЕНіЭ ї¬°б °ьё®АЪ
- C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\CJCTQ25G\ismupdate[1].php
- %APPDATA%\Microsoft\Internet Explorer\Quick LaunchАОЕНіЭ ї¬°б °ьё®АЪ
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\ismupdate[1].php
- %TEMP%\nsg2.tmp\SimpleSC.dll
- %TEMP%\nsg2.tmp\System.dll
- %TEMP%\nsg2.tmp\Processes.dll
- %PROGRAM_FILES%\isu\Uninstall.exe
- %PROGRAM_FILES%\isu\isus.exe
- %TEMP%\nsg2.tmp\System.dll
- %TEMP%\nsg2.tmp\SimpleSC.dll
- %TEMP%\nsg2.tmp\Processes.dll
- 'vo######te.windowsnas.co.kr':80
- vo######te.windowsnas.co.kr/ism/isu.exe
- vo######te.windowsnas.co.kr/ismupdate.php
- DNS ASK vo######te.windowsnas.co.kr
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'