Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'db31c9b' = '"<LS_APPDATA>\gynot\gynot.exe"'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'db31c9b' = '"<LS_APPDATA>\gynot\gynot.exe"'
- '%TEMP%\WindowsXP-KB968930-x86-ENG.exe' /quiet /norestart
- '%TEMP%\WindowsXP-KB968930-x86-ENG.exe' (загружен из сети Интернет)
- '<SYSTEM32>\regsvr32.exe'
- <SYSTEM32>\regsvr32.exe
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1] '1206' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1] '2300' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1] '1809' = '00000003'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1206' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '2300' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1809' = '00000003'
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\microsoft[1]
- <LS_APPDATA>\gynot\gynot.exe
- %TEMP%\WindowsXP-KB968930-x86-ENG.exe
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\WindowsXP-KB968930-x86-ENG[1].exe
- %APPDATA%\System.dll
- %APPDATA%\MilkwortIsotronBotChuckle
- %TEMP%\nsn2.tmp
- %APPDATA%\mystics.dll
- %APPDATA%\Dummy.dic
- '19#.#03.114.24':80
- '20#.#08.158.211':443
- '83.##3.31.142':80
- '81.##3.230.98':443
- '42.##.249.234':443
- '12#.#07.20.82':80
- '15#.#49.41.145':8080
- '16#.#0.10.88':80
- '18#.#70.169.127':80
- '23#.#1.114.108':80
- '13.##5.49.114':80
- '10#.#03.4.129':80
- '60.#.165.60':80
- '14#.#01.2.188':80
- '96.#.76.187':80
- '68.##.234.164':80
- '94.##8.101.216':80
- '16#.#6.252.48':8080
- '11#.#36.129.144':80
- '20#.#15.202.246':80
- '21#.73.6.69':443
- '76.##3.32.14':80
- '20#.#6.232.182':80
- '35.##.13.104':80
- '55.##6.245.10':443
- '18#.#54.67.84':80
- '24#.#07.74.169':80
- '22#.#8.240.77':80
- '19#.#94.35.29':443
- '62.##6.55.25':80
- '22#.#41.98.195':80
- '24#.#37.138.223':80
- '21#.#95.189.139':80
- http://do#####d.microsoft.com/download/E/C/E/ECE99583-2003-455D-B681-68DB610B44A4/WindowsXP-KB968930-x86-ENG.exe via 20#.#6.232.182
- http://microsoft.com/ via 20#.#6.232.182
- DNS ASK do#####d.microsoft.com
- DNS ASK microsoft.com