Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Application Layer Gateway' = '%CommonProgramFiles%\alg.exe'
- '%CommonProgramFiles%\alg.exe'
- '%TEMP%\_ir_sf_temp_0\irsetup.exe' __IRAOFF:654882 "__IRAFN:<Полный путь к вирусу>" "__IRCT:1" "__IRTSS:0" "__IRSID:S-1-5-21-2052111302-484763869-725345543-1003"
- C:\ErrLog.txt
- %CommonProgramFiles%\alg.exe
- %TEMP%\_ir_sf_temp_0\irsetup.exe
- %TEMP%\_ir_sf_temp_0\irsetup.dat
- %TEMP%\_ir_sf_temp_0\irsetup.exe
- %TEMP%\_ir_sf_temp_0\irsetup.dat
- 'wp#d':80
- 'www.so###soft.com':80
- 'localhost':1037
- www.so###soft.com/products/c2/user/yogi/l.php?c=#################################################
- www.so###soft.com/products/c2/user/yogi/g.php?c=#################################################
- www.so###soft.com/products/c2/user/yogi/a.php?c=#################################################
- wp#d/wpad.dat
- DNS ASK wp#d
- DNS ASK www.so###soft.com
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'MS_WINHELP' WindowName: ''