Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Application Layer Gateway' = '%CommonProgramFiles%\alg.exe'
- %CommonProgramFiles%\alg.exe
- %TEMP%\_ir_sf_temp_0\irsetup.exe __IRAOFF:654882 "__IRAFN:<Полный путь к вирусу>" "__IRCT:1" "__IRTSS:0" "__IRSID:S-1-5-21-2052111302-484763869-725345543-1003"
- %CommonProgramFiles%\alg.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\a[1].php
- C:\ErrLog.txt
- %TEMP%\_ir_sf_temp_0\irsetup.exe
- %TEMP%\_ir_sf_temp_0\irsetup.dat
- %TEMP%\_ir_sf_temp_0\irsetup.exe
- %TEMP%\_ir_sf_temp_0\irsetup.dat
- 'wp#d':80
- 'www.so###soft.com':80
- 'localhost':1035
- www.so###soft.com/products/c2/user/vmedia/l.php?c=#################################################
- wp#d/wpad.dat
- www.so###soft.com/products/c2/user/vmedia/a.php?c=#################################################
- DNS ASK wp#d
- DNS ASK www.so###soft.com
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'MS_WINHELP' WindowName: ''