Техническая информация
- '<SYSTEM32>\bpk.exe'
- '%TEMP%\RarSFX0\MULTHACK.exe'
- '%TEMP%\RarSFX0\rinst.exe'
- '%WINDIR%\explorer.exe' http://www.ch###ing-x.com/
- <SYSTEM32>\inst.dat
- <SYSTEM32>\bpkhk.dll
- <SYSTEM32>\bpk.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\cheating-x[1]
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\ban[1].txt
- <SYSTEM32>\rinst.exe
- <SYSTEM32>\pk.bin
- %TEMP%\RarSFX0\bpkhk.dll
- %TEMP%\RarSFX0\inst.dat
- %TEMP%\RarSFX0\pk.bin
- %TEMP%\RarSFX0\rinst.exe
- %TEMP%\RarSFX0\MULTHACK.exe
- %TEMP%\RarSFX0\bpk.exe
- %TEMP%\RarSFX0\inst.dat
- %TEMP%\RarSFX0\rinst.exe
- %TEMP%\RarSFX0\MULTHACK.exe
- %TEMP%\RarSFX0\pk.bin
- %TEMP%\RarSFX0\bpk.exe
- %TEMP%\RarSFX0\bpkhk.dll
- 'localhost':1039
- 'www.ch###ing-x.com':80
- 'localhost':1036
- 'st#######ptap.altervista.org':80
- www.ch###ing-x.com/
- st#######ptap.altervista.org/ban.txt
- DNS ASK www.ch###ing-x.com
- DNS ASK st#######ptap.altervista.org
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: '' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: '' WindowName: 'PKL Window'