Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Application Layer Gateway' = '%CommonProgramFiles%\alg.exe'
- %TEMP%\_ir_sf_temp_0\irsetup.exe __IRAOFF:654882 "__IRAFN:<Текущая директория>\silent.exe" "__IRCT:1" "__IRTSS:0" "__IRSID:S-1-5-21-2052111302-484763869-725345543-1003"
- %CommonProgramFiles%\alg.exe
- <Текущая директория>\Lead Samurai.exe
- <Текущая директория>\silent.exe
- %TEMP%\dw.log
- C:\ErrLog.txt
- %CommonProgramFiles%\alg.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\a[1].php
- %TEMP%\219F6.dmp
- <Текущая директория>\Lead Samurai.exe
- %TEMP%\nsh2.tmp
- <Текущая директория>\silent.exe
- %TEMP%\_ir_sf_temp_0\irsetup.dat
- %TEMP%\_ir_sf_temp_0\irsetup.exe
- %TEMP%\_ir_sf_temp_0\irsetup.exe
- %TEMP%\_ir_sf_temp_0\irsetup.dat
- 'wp#d':80
- 'www.so###soft.com':80
- 'localhost':1035
- www.so###soft.com/products/c2/user/bevjones/l.php?c=#################################################
- www.so###soft.com/products/c2/user/bevjones/g.php?c=#################################################
- www.so###soft.com/products/c2/user/bevjones/a.php?c=#################################################
- wp#d/wpad.dat
- DNS ASK wp#d
- DNS ASK www.so###soft.com
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'MS_WINHELP' WindowName: ''