Техническая информация
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Windows Live' = '%TEMP%\óîáúî.exe'
- winhost.exe
- %TEMP%\óîáúî.exe
- %TEMP%\winhost.exe
- %TEMP%\badhackers_wallhack.exe
- %TEMP%\cetrainers\cetc61c.tmp\cet_archive.dat
- %TEMP%\cetrainers\cetc61c.tmp\badhackers_wallhack.exe
- %TEMP%\cetrainers\cetc61c.tmp\extracted\cet_trainer.cetrainer
- %TEMP%\cetrainers\cetc61c.tmp\extracted\defines.lua
- %TEMP%\cetrainers\cetc61c.tmp\extracted\badhackers_wallhack.exe
- %TEMP%\cetrainers\cetc61c.tmp\extracted\lua5.1-32.dll
- %TEMP%\cetrainers\cetc61c.tmp\extracted\win32\dbghelp.dll
- %TEMP%\cetrainers\cetc61c.tmp\extracted\cet_trainer.cetrainer
- DNS ASK le#####1337.no-ip.org
- '%TEMP%\óîáúî.exe'
- '%TEMP%\winhost.exe'
- '%TEMP%\badhackers_wallhack.exe'
- '%TEMP%\cetrainers\cetc61c.tmp\badhackers_wallhack.exe'
- '%TEMP%\cetrainers\cetc61c.tmp\extracted\badhackers_wallhack.exe' "%TEMP%\cetrainers\CETC61C.tmp\extracted\CET_TRAINER.CETRAINER"