Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'db31c9b' = '"<LS_APPDATA>\cilid\cilid.exe"'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'db31c9b' = '"<LS_APPDATA>\cilid\cilid.exe"'
- '' (загружен из сети Интернет)
- <SYSTEM32>\regsvr32.exe
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1206' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '2300' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1809' = '00000003'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1] '1206' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1] '2300' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1] '1809' = '00000003'
- %TEMP%\nse2.tmp
- %APPDATA%\HomologueSubdistrict
- %APPDATA%\annotation.css.xml
- %APPDATA%\Sabbatarians.dll
- %APPDATA%\System.dll
- %APPDATA%\FF32A6D9-ACAE-42F5-AE3C-A6CAF0BDEBA9\<Имя файла>.exe
- %TEMP%\nsa4.tmp
- <LS_APPDATA>\cilid\cilid.exe
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\microsoft[1]
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\WindowsXP-KB968930-x86-ENG[1].exe
- %TEMP%\WindowsXP-KB968930-x86-ENG.exe
- <Полный путь к файлу>
- '20#.#6.232.182':80
- '10#.#3.187.56':80
- '19#.#4.22.117':8080
- '6.##.252.129':80
- '20#.#94.14.78':80
- '13#.#5.149.51':80
- '65.##8.229.73':80
- '19#.#07.172.75':80
- '12#.#8.39.217':80
- '22#.#19.204.66':80
- '11#.#50.200.50':80
- '16#.#4.80.145':80
- '14#.#0.96.235':80
- '10#.#77.127.228':80
- '12#.#68.120.145':80
- '21#.#97.100.4':443
- '21#.#35.242.209':80
- '10#.#40.153.221':80
- '17#.#8.111.92':80
- '12#.#2.32.245':80
- '68.##0.196.92':80
- '21#.#52.204.251':80
- '18#.#4.41.71':80
- '43.##2.77.212':8080
- '25#.#0.24.186':80
- '20#.#77.107.179':8080
- '17#.#5.29.30':80
- '72.##5.90.60':443
- '24#.#6.55.71':443
- '14#.#29.210.58':80
- '15#.#2.215.200':80
- http://microsoft.com/ via 20#.#6.232.182
- http://download.microsoft.com/download/E/C/E/ECE99583-2003-455D-B681-68DB610B44A4/WindowsXP-KB968930-x86-ENG.exe via 20#.#6.232.182
- DNS ASK microsoft.com
- DNS ASK download.microsoft.com
- '<Полный путь к файлу>'
- '%APPDATA%\FF32A6D9-ACAE-42F5-AE3C-A6CAF0BDEBA9\<Имя файла>.exe'
- '%TEMP%\WindowsXP-KB968930-x86-ENG.exe' /quiet /norestart
- '<SYSTEM32>\regsvr32.exe'