Technical Information
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] 'shell' = 'explorer.exe,%APPDATA%\Other.res'
- '%TEMP%\1.tmp'
- '%TEMP%\1.tmp' (downloaded from the Internet)
- '<SYSTEM32>\svchost.exe'
- <SYSTEM32>\svchost.exe
- %TEMP%\1.tmp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\WindowsXP-KB936929-SP3-x86-ENU[1].exe
- %APPDATA%\Other.res
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\Pony[1].exe
- '20#.#6.232.182':80
- 'lo###popus.net':80
- 'localhost':1038
- 20#.#6.232.182/download/d/3/0/d30e32d8-418a-469d-b600-f32ce3edf42d/WindowsXP-KB936929-SP3-x86-ENU.exe
- lo###popus.net/Pony.exe
- DNS ASK do#####d.microsoft.com
- DNS ASK lo###popus.net