Техническая информация
- [<HKLM>\SOFTWARE\Classes\irc\Shell\open\command] '' = '"%PROGRAM_FILES%\SOHBET1698\SOHBET169\Asi_Mavi.exe" -noconnect'
- [<HKLM>\SOFTWARE\Classes\ChatFile\Shell\open\command] '' = '"%PROGRAM_FILES%\SOHBET1698\SOHBET169\Asi_Mavi.exe" -noconnect'
- %PROGRAM_FILES%\SOHBET1698\SOHBET169\Asi_Mavi.exe
- %WINDIR%\msagent\agentsvr.exe -Embedding
- %WINDIR%\regedit.exe /S Asi_Mavi.php
- %PROGRAM_FILES%\SOHBET1698\SOHBET169\scripts\script2.ini
- %PROGRAM_FILES%\SOHBET1698\SOHBET169\scripts\script3.ini
- %PROGRAM_FILES%\SOHBET1698\SOHBET169\scripts\remote.ini
- %PROGRAM_FILES%\SOHBET1698\SOHBET169\scripts\script1.ini
- %PROGRAM_FILES%\SOHBET1698\SOHBET169\scripts\vars.ini
- %HOMEPATH%\Desktop\SOHBET169.lnk
- %PROGRAM_FILES%\SOHBET1698\SOHBET169\Uninstall.ini
- %PROGRAM_FILES%\SOHBET1698\SOHBET169\servers.ini
- %PROGRAM_FILES%\SOHBET1698\SOHBET169\Uninstall.exe
- %PROGRAM_FILES%\SOHBET1698\SOHBET169\Asi_Mavi.exe
- %PROGRAM_FILES%\SOHBET1698\SOHBET169\Asi_Mavi.php
- %TEMP%\$inst\2.tmp
- %TEMP%\$inst\temp_0.tmp
- %PROGRAM_FILES%\SOHBET1698\SOHBET169\Asi_Mavi1.jpg
- %PROGRAM_FILES%\SOHBET1698\SOHBET169\popups.ini
- %PROGRAM_FILES%\SOHBET1698\SOHBET169\remote3.ttf
- %PROGRAM_FILES%\SOHBET1698\SOHBET169\Asi_Mavi2.jpg
- %PROGRAM_FILES%\SOHBET1698\SOHBET169\mirc.ini
- %TEMP%\$inst\2.tmp
- %TEMP%\$inst\temp_0.tmp
- ClassName: '..::32' WindowName: ''
- ClassName: 'RegEdit_RegEdit' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: '..::' WindowName: ''