Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'HNG' = '"<Полный путь к файлу>"'
- [<HKLM>\System\CurrentControlSet\Services\GarenaCIG] 'ImagePath' = '"%ALLUSERSPROFILE%\Application Data\GarenaCIG\GarenaCIG.exe" --service'
- %ALLUSERSPROFILE%\application data\garenacig\garenacig.zip
- %ALLUSERSPROFILE%\application data\garenacig\garenacig.exe
- <Текущая директория>\encryption.dll
- http://do####ad.gcafex.com/update.html
- http://cd#.#cafex.com/GarenaCIG.zip
- http://cd#.#cafex.com/Encryption_xp_x86.dll
- DNS ASK do####ad.gcafex.com
- DNS ASK au##.gcafex.com
- DNS ASK cd#.#cafex.com
- '<SYSTEM32>\sc.exe' create GarenaCIG DisplayName= "GCafe Service" binPath= "\"%ALLUSERSPROFILE%\Application Data\GarenaCIG\GarenaCIG.exe\" --service"