Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\AppMgmt] 'Start' = '00000002'
- '%TEMP%\svchost.bat'
- '<SYSTEM32>\dumprep.exe' 1108 -dm 7 7 %TEMP%\WERd0d5.dir00\svchost.exe.hdmp 16325836412032144
- '<SYSTEM32>\dumprep.exe' 1108 -dm 7 7 %TEMP%\WERd0d5.dir00\svchost.exe.mdmp 16325836412032132
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\9YQ0AHXA\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\4TUJ89MN\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\8RSBCDEF\desktop.ini
- %TEMP%\WERd0d5.dir00\svchost.exe.mdmp
- %TEMP%\WERd0d5.dir00\manifest.txt
- %TEMP%\WERd0d5.dir00\appcompat.txt
- %TEMP%\WERd0d5.dir00\svchost.exe.hdmp
- %TEMP%\msmqinst.ax
- %TEMP%\Б`ІО©ІЇµ®СЄшЁз.pdf
- %TEMP%\svchost.bat
- %TEMP%\winsvc.dll
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\WLA3CXMB\desktop.ini
- %WINDIR%\Temp\msmqinst.ax
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\4TUJ89MN\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\9YQ0AHXA\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\WLA3CXMB\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\8RSBCDEF\desktop.ini