Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Control\Print\Providers\1831461984] 'Name' = '%TEMP%\srv988.tmp'
- [<HKLM>\SYSTEM\ControlSet001\Services\srv988] 'Start' = '00000002'
- <SYSTEM32>\spoolsv.exe
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\HFNBQGQ5\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\JE0ATLST\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\FYQIABUM\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\01Y34567\desktop.ini
- %TEMP%\srv988.tmp
- %TEMP%\srv988.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\JE0ATLST\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\FYQIABUM\desktop.ini
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\HFNBQGQ5\desktop.ini
- %TEMP%\srv988.tmp
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\01Y34567\desktop.ini
- '<IP-адрес в локальной сети>':80
- 'localhost':1134
- '<IP-адрес в локальной сети>':445
- '<IP-адрес в локальной сети>':139