Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\appsrv] 'Start' = '00000002'
- '<SYSTEM32>\appsrv.exe'
- '%WINDIR%\explorer.exe'
- %WINDIR%\explorer.exe
- C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\LBMMC3H3\do[2].exe
- C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\LBMMC3H3\do[3].exe
- C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\MOE00UY1\do[1].exe
- <SYSTEM32>\appsrv.exe
- C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\CJCTQ25G\do[1].exe
- C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\LBMMC3H3\do[1].exe
- <SYSTEM32>\appsrv.exe
- 'localhost':1040
- 'localhost':1042
- 'localhost':1044
- 'localhost':1036
- '<IP-адрес в локальной сети>':80
- 'localhost':1038
- <IP-адрес в локальной сети>/do.exe