Техническая информация
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'drd32.exe' = '%TEMP%\drd32.exe'
- drd32.exe
- ClassName: 'TibiaClient', WindowName: ''
- %TEMP%\bot.exe
- %TEMP%\reg32.exe
- %TEMP%\_ir_sf_temp_0\irsetup.exe
- %TEMP%\_ir_sf_temp_0\lua5.1.dll
- %TEMP%\drd32.exe
- %TEMP%\tbi72.dll
- %TEMP%\_ir_sf_temp_0\irsetup.dat
- %TEMP%\_ir_sf_temp_0\irimg1.jpg
- %TEMP%\_ir_sf_temp_0\irimg2.jpg
- %TEMP%\_ir_sf_temp_0\eula.txt
- %APPDATA%\tbi72.dll
- %TEMP%\_ir_sf_temp_0\irsetup.dat
- '34.##9.100.209':443
- ClassName: 'EDIT' WindowName: ''
- ClassName: 'TibiaClientPreview' WindowName: ''
- '%TEMP%\reg32.exe'
- '%TEMP%\bot.exe'
- '%TEMP%\_ir_sf_temp_0\irsetup.exe' __IRAOFF:1749498 "__IRAFN:%TEMP%\bot.exe" "__IRCT:3" "__IRTSS:2621767" "__IRSID:S-1-5-21-3691498038-2086406363-2140527554-1000"
- '%TEMP%\drd32.exe'