Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'dso32' = '%TEMP%\dsoqq.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\AVPsys] 'ImagePath' = '<DRIVERS>\cdaudio.sys'
- <DRIVERS>\cdaudio.sys
- '%ProgramFiles%\Internet Explorer\IEXPLORE.EXE'
- %WINDIR%\Explorer.EXE
- Библиотека-обработчик для всех процессов: %TEMP%\dsoqq0.dll
- ClassName: 'AVP.Product_Notification' WindowName: ''
- ClassName: 'AVP.AlertDialog' WindowName: ''
- <SYSTEM32>\dllcache\cdaudio.sys.new
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\am1[1].rar
- %TEMP%\am1.rar
- <DRIVERS>\SET2.tmp
- %TEMP%\dsoqq.exe
- %TEMP%\dsoqq0.dll
- <DRIVERS>\SET1.tmp
- %TEMP%\dsoqq0.dll
- %TEMP%\dsoqq.exe
- %TEMP%\am1.rar
- <DRIVERS>\SET1.tmp
- <DRIVERS>\cdaudio.sys
- 'www.ya###fvo.com':80
- 'localhost':1036
- http://www.ya###fvo.com/1mg/am1.rar
- DNS ASK www.ya###fvo.com
- ClassName: 'IEFrame' WindowName: ''