Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'GarenaCIG' = '"%ALLUSERSPROFILE%\Application Data\GarenaCIG\3.0.849\GarenaCIG.exe" --tray'
- [<HKLM>\SYSTEM\ControlSet001\Services\GarenaCIG] 'Start' = '00000002'
- '%ALLUSERSPROFILE%\Application Data\GarenaCIG\3.0.849\GarenaCIG.exe'
- '%ALLUSERSPROFILE%\Application Data\GarenaCIG\3.0.849\GarenaCIG.exe' --service
- 'C:\bot\ggcoutside\GarenaCIG.exe' --install 853SAMWK9PGXDBPY --silence
- %ALLUSERSPROFILE%\Application Data\GarenaCIG\3.0.849\GarenaCIG.exe
- C:\bot\ggcoutside\GarenaCIG.exe
- 'localhost':1043
- 'cd#.##renanow.com':80
- 'gc#####2.garenanow.com':443
- 'localhost':1038
- 'localhost':1040
- cd#.##renanow.com/ywjah/mc_gca.js
- cd#.##renanow.com/gca/cig/update/update
- DNS ASK cd#.##renanow.com
- DNS ASK gc#####2.garenanow.com
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'EDIT' WindowName: '(null)'