Техническая информация
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] '%ProgramFiles%\Nwiz Drivers\nwiz.exe' = '%ProgramFiles%\Nwiz Drivers\nwiz.exe'
- ClassName: 'TibiaClient', WindowName: ''
- %WINDIR%\dat.exe
- %WINDIR%\unrar.exe
- %WINDIR%\ulg.exe
- %ProgramFiles%\nwiz drivers\nwiz.exe
- 'mo#####.map.fastly.net':443
- DNS ASK mo#####.map.fastly.net
- ClassName: 'EDIT' WindowName: ''
- '%WINDIR%\unrar.exe' e -o- -pJA*@)A*#R$Srf1f$#112d dat.exe
- '%WINDIR%\ulg.exe'
- '%WINDIR%\syswow64\cmd.exe' /c start /min <SYSTEM32>\cmd.exe /c "cd /d %WINDIR%&unrar.exe e -o- -pJA*@)A*#R$Srf1f$#112d dat.exe&start ulg.exe&del unrar.exe
- '%WINDIR%\syswow64\cmd.exe' /c "cd /d %WINDIR%&unrar.exe e -o- -pJA*@)A*#R$Srf1f$#112d dat.exe&start ulg.exe&del unrar.exe