Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'GarenaCIG' = '"%ALLUSERSPROFILE%\Application Data\GarenaCIG\3.0.857\GarenaCIG.exe" --tray'
- [<HKLM>\SYSTEM\ControlSet001\Services\GarenaCIG] 'Start' = '00000002'
- '%ALLUSERSPROFILE%\Application Data\GarenaCIG\3.0.857\GarenaCIG.exe'
- '%ALLUSERSPROFILE%\Application Data\GarenaCIG\3.0.857\GarenaCIG.exe' --service
- '%TEMP%\RarSFX0\GarenaCIG.exe' --install VN20130731X8X3SB --silence
- %ALLUSERSPROFILE%\Application Data\GarenaCIG\3.0.857\GarenaCIG.exe
- %TEMP%\RarSFX0\GarenaCIG.exe
- %TEMP%\RarSFX0\GarenaCIG.exe
- 'gc#####2.garenanow.com':443
- 'cd#.##renanow.com':80
- 'localhost':1041
- 'localhost':1037
- 'localhost':1038
- cd#.##renanow.com/gca/cig/update/update
- cd#.##renanow.com/ywjah/mc_gca.js
- DNS ASK cd#.##renanow.com
- DNS ASK gc#####2.garenanow.com
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'EDIT' WindowName: '(null)'