Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '' = '"%APPDATA%\core.exe"'
- [<HKLM>\SYSTEM\ControlSet001\Services\WinModule] 'Start' = '00000002'
- %APPDATA%\core.exe
- %WINDIR%\Explorer.EXE
- %TEMP%\wscript.exe
- %TEMP%\i86.exe
- %APPDATA%\Tibia\module.dll
- %APPDATA%\core.exe
- %APPDATA%\Tibia\Automap\core.dll
- %TEMP%\d86.dll
- %TEMP%\d64.dll
- %TEMP%\x64.dll
- %TEMP%\i64.exe
- %TEMP%\x86.dll
- %APPDATA%\core.exe
- %APPDATA%\Tibia\Automap\core.dll
- %APPDATA%\Tibia\module.dll
- 'ul#####e-recovery.pl':80
- ul#####e-recovery.pl/engine/autoUpdate.php
- DNS ASK ul#####e-recovery.pl
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'EDIT' WindowName: ''