Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'update.secure' = '<SYSTEM32>\taskeng.exe'
- [<HKLM>\SOFTWARE\Microsoft\Active Setup\Installed Components\{98216E7A-8176-8F15-DFDA-82FDDF08C4A6}] 'StubPath' = '<SYSTEM32>\taskeng.exe'
- '%TEMP%\Memory.exe'
- '%TEMP%\here.exe'
- '<SYSTEM32>\cmd.exe' /c C:\melt1.bat
- ClassName: 'PROCMON_WINDOW_CLASS' WindowName: ''
- ClassName: 'RegMonClass' WindowName: ''
- ClassName: 'FileMonClass' WindowName: ''
- <SYSTEM32>\taskeng.exe
- C:\melt1.bat
- %TEMP%\here.exe
- %TEMP%\Memory.exe
- %TEMP%\here.exe
- 'up####.servegame.com':6001
- DNS ASK up####.servegame.com
- ClassName: 'ThunderRT6FormDC' WindowName: ''
- ClassName: 'ThunderRT6FormDC' WindowName: 'Shareware Cheater v 3.0'
- ClassName: 'Shell_TrayWnd' WindowName: ''