Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\Windows Update] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\BITS] 'Start' = '00000002'
- <SYSTEM32>\svchost.exe -k krnlsrvc
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\0TM1Y5KN\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\RDQFSHUJ\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\MZIT8JSD\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\RDQFSHUJ\aplus2[1].jpg
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\50KSDX2C\desktop.ini
- %TEMP%\111984_res.tmp
- %TEMP%\106421_res.tmp
- <SYSTEM32>\wbem\secrcw64.mof
- <SYSTEM32>\Rnnetvb.dll
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\0TM1Y5KN\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\MZIT8JSD\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\50KSDX2C\desktop.ini
- <SYSTEM32>\RamptsC.dll
- <SYSTEM32>\c_O95OO.nls
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\RDQFSHUJ\desktop.ini
- '17#.#6.16.55':80
- 'localhost':1035
- 17#.#6.16.55/aplus2.jpg