Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'db31c9b' = '"<LS_APPDATA>\vetal\vetal.exe"'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'db31c9b' = '"<LS_APPDATA>\vetal\vetal.exe"'
- '%TEMP%\WindowsXP-KB968930-x86-ENG.exe' /quiet /norestart
- '%TEMP%\WindowsXP-KB968930-x86-ENG.exe' (загружен из сети Интернет)
- '<SYSTEM32>\regsvr32.exe'
- <SYSTEM32>\regsvr32.exe
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1] '1206' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1] '2300' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1] '1809' = '00000003'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1206' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '2300' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1809' = '00000003'
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\WindowsXP-KB968930-x86-ENG[1].exe
- %TEMP%\WindowsXP-KB968930-x86-ENG.exe
- <LS_APPDATA>\vetal\vetal.exe
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\microsoft[1]
- '81.##2.126.46':80
- '75.##7.170.204':443
- '17#.#26.8.118':80
- '52.##.22.173':80
- '21#.#62.99.205':8080
- '20#.#8.202.222':80
- '20#.#6.232.182':80
- '22#.#09.17.237':8080
- '24#.#02.56.222':80
- http://do#####d.microsoft.com/download/E/C/E/ECE99583-2003-455D-B681-68DB610B44A4/WindowsXP-KB968930-x86-ENG.exe via 20#.#6.232.182
- http://microsoft.com/ via 20#.#6.232.182
- DNS ASK do#####d.microsoft.com
- DNS ASK microsoft.com