Техническая информация
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'DSF' = '%WINDIR%\Installer\6C1G0BA4-H15G-4F37-BD14-145DG16821EK}\installer.exe'
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'DSF' = '%WINDIR%\Installer\6C1G0BA4-H15G-4F37-BD14-145DG16821EK}\installer.exe'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'ACPI' = '%WINDIR%\Installer\6C1G0BA4-H15G-4F37-BD14-145DG16821EK}\installer.exe'
- %WINDIR%\syswow64\explorer.exe
- %WINDIR%\explorer.exe
- launcher.exe
- installer.exe
- ClassName: 'OLLYDBG', WindowName: ''
- %TEMP%\65d5a3b8
- %WINDIR%\installer\6c1g0ba4-h15g-4f37-bd14-145dg16821ek}\installer.exe
- %TEMP%\xx--xx--xx.txt
- %TEMP%\xxx.xxx
- %TEMP%\uuu.uuu
- %TEMP%\xx--xx--xx.txt
- %TEMP%\uuu.uuu
- %TEMP%\xxx.xxx
- %TEMP%\uuu.uuu
- %TEMP%\xxx.xxx
- DNS ASK go######c1.servegame.com
- '%WINDIR%\installer\6c1g0ba4-h15g-4f37-bd14-145dg16821ek}\installer.exe'
- '%WINDIR%\syswow64\explorer.exe'
- '%ProgramFiles(x86)%\opera\launcher.exe'