Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'UpInit164346' = 'RUNDLL32.EXE C:\RECYCLER\20132243\GameUpdate.INI,LoaderEntry'
- '%WINDIR%\Temp\yong.exe'
- '%WINDIR%\Temp\bots.exe'
- '<SYSTEM32>\rundll32.exe' C:\RECYCLER\20132243\GameUpdate.INI,LoaderEntry
- C:\RECYCLER\20132243\GameUpdate.INI
- C:\RECYCLER\20132243\ntlbin
- C:\RECYCLER\Config.ini
- %WINDIR%\Temp\bots.exe
- %WINDIR%\Temp\yong.exe
- %WINDIR%\Temp\yong.exe в C:\RECYCLER\20132243\GameUpdate.INI
- 'wa#####014.gnway.net':6014
- DNS ASK wa#####014.gnway.net
- ClassName: 'Indicator' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''