Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '96f8d30' = '"<LS_APPDATA>\udynaw\udynaw.exe"'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '96f8d30' = '"<LS_APPDATA>\udynaw\udynaw.exe"'
- '' (загружен из сети Интернет)
- <SYSTEM32>\regsvr32.exe
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1206' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '2300' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1809' = '00000003'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1] '1206' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1] '2300' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1] '1809' = '00000003'
- <LS_APPDATA>\udynaw\udynaw.exe
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\microsoft[1]
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\WindowsXP-KB968930-x86-ENG[1].exe
- %TEMP%\WindowsXP-KB968930-x86-ENG.exe
- <Полный путь к файлу>
- '20#.#6.232.182':80
- '62.##2.173.173':80
- '18#.#40.116.25':8080
- '92.##1.136.50':80
- '94.##5.194.97':80
- '11#.#94.79.168':80
- '18#.#3.196.44':80
- '11#.#1.32.140':80
- '24#.#18.237.216':8080
- '6.##.247.6':80
- '16#.#52.47.202':80
- '21#.#41.94.142':80
- '18#.#7.127.23':80
- '17#.#01.106.215':80
- '6.###.27.214':80
- '12#.#5.161.194':80
- '55.##.179.10':8080
- '24#.#22.217.187':80
- '36.##8.32.64':80
- '19#.#08.132.115':80
- '72.##2.188.61':80
- '12#.#03.237.74':80
- '32.##.200.222':80
- '72.##7.51.44':80
- '21#.#0.179.250':80
- http://microsoft.com/ via 20#.#6.232.182
- http://download.microsoft.com/download/E/C/E/ECE99583-2003-455D-B681-68DB610B44A4/WindowsXP-KB968930-x86-ENG.exe via 20#.#6.232.182
- DNS ASK microsoft.com
- DNS ASK download.microsoft.com
- '<Полный путь к файлу>'
- '%TEMP%\WindowsXP-KB968930-x86-ENG.exe' /quiet /norestart
- '<SYSTEM32>\regsvr32.exe'