Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] ' krcdh' = '"<LS_APPDATA>\bepab\bepab.exe"'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] ' krcdh' = '"<LS_APPDATA>\bepab\bepab.exe"'
- '%TEMP%\WindowsXP-KB968930-x86-ENG.exe' /quiet /norestart
- '%TEMP%\WindowsXP-KB968930-x86-ENG.exe' (загружен из сети Интернет)
- '<SYSTEM32>\regsvr32.exe'
- <SYSTEM32>\regsvr32.exe
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1] '1206' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1] '2300' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1] '1809' = '00000003'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1206' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '2300' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1809' = '00000003'
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\WindowsXP-KB968930-x86-ENG[1].exe
- %TEMP%\WindowsXP-KB968930-x86-ENG.exe
- <LS_APPDATA>\bepab\bepab.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\microsoft[1]
- '88.##9.49.74':443
- '19.#0.1.188':80
- '15#.#22.55.54':80
- '68.##9.140.82':8080
- '6.###.132.237':80
- '80.##0.96.221':80
- '20#.#83.137.138':80
- '22#.#23.143.121':80
- '20#.#24.42.43':80
- '93.##4.255.147':80
- '22#.#0.122.163':80
- '24#.#80.133.60':80
- '15#.#53.108.109':80
- '14#.#26.20.225':443
- '1.##.116.15':8080
- '21#.#44.210.185':80
- '54.##9.32.170':80
- '25#.#40.115.69':80
- '24#.#1.69.153':80
- '19#.#81.66.7':80
- '21#.#41.70.255':80
- '15#.#80.197.155':80
- '20#.#27.190.236':443
- '24#.#27.154.174':80
- '20#.#73.175.224':80
- '21#.#96.99.5':80
- '20#.#6.232.182':80
- '16#.#6.43.177':8080
- '14#.#98.5.149':8080
- '45.##0.171.69':80
- '22.##9.247.19':80
- '22#.#89.65.101':80
- '15#.#5.65.135':80
- '13.##.157.203':80
- '13#.#67.145.133':80
- '25#.#27.175.233':80
- '13#.#2.126.50':80
- '10#.#1.236.195':80
- http://do#####d.microsoft.com/download/E/C/E/ECE99583-2003-455D-B681-68DB610B44A4/WindowsXP-KB968930-x86-ENG.exe via 20#.#6.232.182
- http://microsoft.com/ via 20#.#6.232.182
- DNS ASK do#####d.microsoft.com
- DNS ASK microsoft.com
- ClassName: 'Indicator' WindowName: ''