Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Application Layer Gateway' = '%CommonProgramFiles%\alg.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'wextract_cleanup0' = 'rundll32.exe <SYSTEM32>\advpack.dll,DelNodeRunDLL32 "%TEMP%\IXP000.TMP\"'
- '%CommonProgramFiles%\alg.exe'
- '%TEMP%\IXP000.TMP\setup.exe'
- '%TEMP%\IXP000.TMP\silent.exe'
- '%TEMP%\_ir_sf_temp_0\irsetup.exe' __IRAOFF:663074 "__IRAFN:%TEMP%\IXP000.TMP\silent.exe" "__IRCT:1" "__IRTSS:0" "__IRSID:S-1-5-21-2052111302-484763869-725345543-1003"
- C:\ErrLog.txt
- %CommonProgramFiles%\alg.exe
- %TEMP%\_ir_sf_temp_0\irsetup.dat
- %TEMP%\IXP000.TMP\setup.exe
- %TEMP%\IXP000.TMP\silent.exe
- %TEMP%\_ir_sf_temp_0\irsetup.exe
- %TEMP%\_ir_sf_temp_0\irsetup.exe
- %TEMP%\_ir_sf_temp_0\irsetup.dat
- 'jo#####nturesonline.net':80
- 'wp#d':80
- 'localhost':1036
- jo#####nturesonline.net/products/subject/user/fadetoblack/g.php?c=#################################################
- jo#####nturesonline.net/products/subject/user/fadetoblack/l.php?c=#################################################
- wp#d/wpad.dat
- DNS ASK jo#####nturesonline.net
- DNS ASK wp#d
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'MS_WINHELP' WindowName: ''