Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] ' rdfnpgyq' = '"<LS_APPDATA>\nareka\nareka.exe"'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] ' rdfnpgyq' = '"<LS_APPDATA>\nareka\nareka.exe"'
- '' (downloaded from the Internet)
- <SYSTEM32>\regsvr32.exe
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1] '1206' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1] '2300' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1] '1809' = '00000003'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1206' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '2300' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1809' = '00000003'
- %TEMP%\YCR5uYz0.H7
- %TEMP%\pINPMCEV.k5
- %TEMP%\index.php1350300127.html
- %TEMP%\historique.htm
- %TEMP%\nsd2.tmp\System.dll
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\WindowsXP-KB968930-x86-ENG[1].exe
- %TEMP%\WindowsXP-KB968930-x86-ENG.exe
- <LS_APPDATA>\nareka\nareka.exe
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\microsoft[1]
- %TEMP%\admin1235763277.html
- %TEMP%\getverifyimage438086310.png
- %TEMP%\close-btn.png
- %TEMP%\gra-logo-alt.png
- %TEMP%\index.php1729461076.javascript
- %TEMP%\normalize.css
- %TEMP%\moc2011Print.css
- %TEMP%\comptaregistry.png
- %TEMP%\linkedin.png
- %TEMP%\nonresponsive.css
- <Full path to file>
- '21#.#42.10.116':80
- '92.#9.69.2':80
- '39.##0.146.51':80
- '19#.#14.2.112':8080
- '40.##.138.49':80
- '17#.#13.33.57':80
- '56.##.84.214':80
- '11#.#01.95.13':80
- '46.##3.122.180':80
- '20#.#9.37.176':80
- '34.##.109.143':80
- '15#.#6.18.54':80
- '40.##.217.139':80
- '81.##.230.19':80
- '11#.#19.174.48':443
- '15#.#6.30.33':80
- '90.##1.101.135':80
- '16#.#22.24.194':80
- '16.##2.193.24':8080
- '11.##7.180.28':80
- '62.##2.115.127':80
- '18#.#19.83.141':80
- '12#.#16.45.68':80
- '57.##6.229.26':80
- '53.##.209.112':8080
- '20#.#6.232.182':80
- '14#.#30.104.45':443
- '1.###.105.109':80
- '15#.#60.51.21':80
- '53.##6.164.74':443
- '56.##.215.170':8080
- '14#.#94.211.54':80
- '45.##3.41.96':80
- '19.##.238.110':8080
- '19#.#5.106.7':80
- '16#.#3.56.84':80
- '97.##7.17.40':80
- '7.##.197.110':80
- http://download.microsoft.com/download/E/C/E/ECE99583-2003-455D-B681-68DB610B44A4/WindowsXP-KB968930-x86-ENG.exe via 20#.#6.232.182
- http://microsoft.com/ via 20#.#6.232.182
- DNS ASK download.microsoft.com
- DNS ASK microsoft.com
- ClassName: 'o7XnxbqpObPndC' WindowName: ''
- ClassName: 'CJqPT' WindowName: ''
- ClassName: 'lPNb7G' WindowName: ''
- ClassName: '2PRTQNMcnfMr' WindowName: ''
- ClassName: 'Gk' WindowName: ''
- ClassName: 'Fy1HCZXNu3K' WindowName: ''
- ClassName: 'IkKRFeOk1G3ni' WindowName: ''
- ClassName: 'EJftB3jvZX5' WindowName: ''
- ClassName: 'TLXPF5' WindowName: ''
- ClassName: '45v2p' WindowName: ''
- ClassName: 'QI8tNRtbo83f' WindowName: ''
- ClassName: 'kMs' WindowName: ''
- ClassName: '3hLYo6Zq5D5jk' WindowName: ''
- ClassName: 'hjeEXuHsRz5' WindowName: ''
- ClassName: 'mxPik3YaZeE' WindowName: ''
- ClassName: '2Hp836yBldS3ZNb' WindowName: ''
- ClassName: 's73Xa0pLapUVuQj' WindowName: ''
- ClassName: '3qzirhI' WindowName: ''
- ClassName: '5Jz5ayrd' WindowName: ''
- ClassName: 'C' WindowName: ''
- ClassName: 'JJFzn0eKUB1' WindowName: ''
- ClassName: 'CzXtoAROv0' WindowName: ''
- ClassName: 'Junm5X' WindowName: ''
- ClassName: 'DKS' WindowName: ''
- ClassName: 'PGxs4vHes6EBge' WindowName: ''
- ClassName: 'lOaPTcL2Zz' WindowName: ''
- ClassName: 'gIga6' WindowName: ''
- ClassName: '2z4tmFoG' WindowName: ''
- ClassName: 'cdzVY4NOthVIB' WindowName: ''
- ClassName: 'TZr0PzFV6MXv' WindowName: ''
- ClassName: 'LJbVdIghfnojLg' WindowName: ''
- ClassName: 'EzutTTt' WindowName: ''
- ClassName: 'EeyuoElJRLE' WindowName: ''
- ClassName: 'ukaNjhDLHiiPE8L' WindowName: ''
- ClassName: 'f' WindowName: ''
- ClassName: 'YjCq03kEbB1nm1' WindowName: ''
- ClassName: 'IYbcrGLIVn' WindowName: ''
- ClassName: 'l' WindowName: ''
- ClassName: 'K' WindowName: ''
- ClassName: '7EKA6MtNkDG' WindowName: ''
- ClassName: 'iRuh3eYdE' WindowName: ''
- ClassName: 'JJS7idVGJDB3' WindowName: ''
- ClassName: 'x' WindowName: ''
- ClassName: 'M07' WindowName: ''
- ClassName: '1UznAenITE' WindowName: ''
- ClassName: 'gYguhQ5xn3f3dU' WindowName: ''
- ClassName: 'rmdkjSLmJHA' WindowName: ''
- ClassName: 'iNAehA' WindowName: ''
- '%TEMP%\WindowsXP-KB968930-x86-ENG.exe' /quiet /norestart
- '<Full path to file>'
- '<SYSTEM32>\regsvr32.exe'