Found this in system32. Ntos.exe causes the machine to connect to 1job1.cn and download runtime.exe, which then downloads and installs rogue av software.
\\ACB
Fatdcuk
Nov 4 2009, 04:49 PM
Many thanks Adam Brock,
I will take a look at the file shortly
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.