Техническая информация
- '<SYSTEM32>\pcpra.exe'
- '<SYSTEM32>\rqdgc.exe'
- %TEMP%\nsv4.tmp\FindProcDLL.dll
- %TEMP%\nsv4.tmp\AccessControl.dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\sogoupid[1].asp
- %TEMP%\nsv4.tmp\ShellLink.dll
- %TEMP%\nsv4.tmp\System.dll
- <SYSTEM32>\IEMon.exe
- %TEMP%\nsi2.tmp\System.dll
- <SYSTEM32>\Log\Install.log
- <SYSTEM32>\Launch_IE.exe
- <SYSTEM32>\pcpra.exe
- %TEMP%\nsv4.tmp\ShellLink.dll
- %TEMP%\nsv4.tmp\System.dll
- %TEMP%\nsv4.tmp\FindProcDLL.dll
- %TEMP%\nsi2.tmp\System.dll
- %TEMP%\nsv4.tmp\AccessControl.dll
- <SYSTEM32>\Launch_IE.exe в <SYSTEM32>\pcpra.exe
- <SYSTEM32>\IEMon.exe в <SYSTEM32>\rqdgc.exe
- 'www.so###-agent.com':80
- www.so###-agent.com/sogoupid.asp?p=##
- DNS ASK www.so###-agent.com