Техническая информация
- %TEMP%\CL_Debug_Log.txt
- %TEMP%\start.bat
- %TEMP%\CR_Debug_Log.txt
- %TEMP%\aut4.tmp
- %TEMP%\start2.bat
- %TEMP%\64.exe
- %TEMP%\20F86.dmp
- %TEMP%\SystemCheck.xml
- %TEMP%\32.exe
- %APPDATA%\1337\asacpiex.dll
- %TEMP%\CheatEngine_v6.8.exe
- %TEMP%\dw.log
- %TEMP%\CheatEngine_v6.4.exe
- %TEMP%\ped-dropper-steam.exe
- %TEMP%\qwilf (2).exe
- %APPDATA%\1337\start.exe
- %TEMP%\1C6A6.dmp
- %TEMP%\nsw2.tmp
- %TEMP%\nsb3.tmp\System.dll
- %TEMP%\CR_Debug_Log.txt
- %TEMP%\SystemCheck.xml
- %TEMP%\start2.bat
- %TEMP%\CL_Debug_Log.txt
- %TEMP%\aut4.tmp
- %TEMP%\nsb3.tmp\System.dll
- %TEMP%\64.exe
- %TEMP%\32.exe
- 'ra#.####ubusercontent.com':443
- 'wp#d':80
- http://11#.#11.111.1/wpad.dat via wp#d
- DNS ASK ra#.####ubusercontent.com
- DNS ASK wp#d
- '%APPDATA%\1337\start.exe'
- '%TEMP%\CL_Debug_Log.txt' e -p"jDWQJkdqkwdqo2m@mdwmsxPAS,sq%" CR_Debug_Log.txt
- '%TEMP%\qwilf (2).exe'
- '%TEMP%\CheatEngine_v6.4.exe'
- '%TEMP%\CheatEngine_v6.8.exe'
- '<SYSTEM32>\cmd.exe' /c start.bat
- '<SYSTEM32>\schtasks.exe' /Create /XML "SystemCheck.xml" /TN "System\SystemCheck"
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 604
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 736