Technical Information
- '<SYSTEM32>\taskkill.exe' /IM Game.exe /F
- '<SYSTEM32>\taskkill.exe' /IM mracsvc.exe /F
- '<SYSTEM32>\taskkill.exe' /IM GameCenter.exe /F
- %WINDIR%\temp\cab903d.tmp
- %WINDIR%\temp\tar903e.tmp
- %WINDIR%\temp\caba63f.tmp
- %WINDIR%\temp\tara640.tmp
- %WINDIR%\temp\caba6ae.tmp
- %WINDIR%\temp\tara6af.tmp
- %WINDIR%\temp\cabbc62.tmp
- %WINDIR%\temp\tarbc63.tmp
- %WINDIR%\temp\cabe882.tmp
- %WINDIR%\temp\tare883.tmp
- %WINDIR%\temp\cab903d.tmp
- %WINDIR%\temp\tar903e.tmp
- %WINDIR%\temp\caba63f.tmp
- %WINDIR%\temp\tara640.tmp
- %WINDIR%\temp\caba6ae.tmp
- %WINDIR%\temp\tara6af.tmp
- %WINDIR%\temp\cabbc62.tmp
- %WINDIR%\temp\tarbc63.tmp
- %WINDIR%\temp\cabe882.tmp
- %WINDIR%\temp\tare883.tmp
- 'localhost':49185
- 'sx#h.ru':443
- 'pk#.goog':80
- http://pk#.goog/gsr1/gsr1.crt
- 'localhost':49185
- 'localhost':49186
- 'sx#h.ru':443
- DNS ASK sx#h.ru
- DNS ASK pk#.goog
- ClassName: '' WindowName: ''
- '<SYSTEM32>\cmd.exe' /c Taskkill /IM Game.exe /F
- '<SYSTEM32>\cmd.exe' /c Taskkill /IM mracsvc.exe /F
- '<SYSTEM32>\cmd.exe' /c Taskkill /IM GameCenter.exe /F
- '<SYSTEM32>\cmd.exe' /c cls