Техническая информация
- [HKCU\Software\Classes\discord-345229890980937739\shell\open\command] '' = '<Полный путь к файлу>'
- ClassName: 'OLLYDBG', WindowName: ''
- ClassName: 'GBDYLLO', WindowName: ''
- ClassName: 'pediy06', WindowName: ''
- ClassName: 'FilemonClass', WindowName: ''
- ClassName: '', WindowName: 'File Monitor - Sysinternals: www.sysinternals.com'
- ClassName: 'PROCMON_WINDOW_CLASS', WindowName: ''
- ClassName: '', WindowName: 'Process Monitor - Sysinternals: www.sysinternals.com'
- ClassName: 'RegmonClass', WindowName: ''
- nul
- %TEMP%\18e190413af045db88dfbd29609eb800.db.ses
- из <Полный путь к файлу> в <Текущая директория>\38kgdmttlwiv.exe
- 'localhost':49692
- 'ap#.##cheats.net':443
- 'localhost':49693
- 'ap#.##cheats.net':443
- DNS ASK ap#.##cheats.net
- ClassName: 'Registry Monitor - Sysinternals: www.sysinternals.com' WindowName: ''
- ClassName: '18467-41' WindowName: ''
- '%WINDIR%\syswow64\cmd.exe' /c sc stop FairPlayKD >nul 2>nul
- '%WINDIR%\syswow64\sc.exe' stop FairPlayKD
- '%WINDIR%\syswow64\cmd.exe' /c net start w32time
- '%WINDIR%\syswow64\net.exe' start w32time
- '%WINDIR%\syswow64\net1.exe' start w32time
- '%WINDIR%\syswow64\cmd.exe' /c cls
- '%WINDIR%\syswow64\cmd.exe' /c w32tm /resync
- '%WINDIR%\syswow64\w32tm.exe' /resync
- '<SYSTEM32>\w32tm.exe' /resync