Техническая информация
- [<HKLM>\SOFTWARE\Classes\irc\Shell\open\command] '' = '"%PROGRAM_FILES%\detayarama\detayarama\sbt.exe" -noconnect'
- [<HKLM>\SOFTWARE\Classes\ChatFile\Shell\open\command] '' = '"%PROGRAM_FILES%\detayarama\detayarama\sbt.exe" -noconnect'
- %PROGRAM_FILES%\detayarama\detayarama\sbt.exe
- %WINDIR%\msagent\agentsvr.exe -Embedding
- %WINDIR%\regedit.exe /S Asi_Mavi.php
- %PROGRAM_FILES%\detayarama\detayarama\popups.ini
- %PROGRAM_FILES%\detayarama\detayarama\remote3.ttf
- %PROGRAM_FILES%\detayarama\detayarama\Asi_Mavi2.jpg
- %PROGRAM_FILES%\detayarama\detayarama\mirc.ini
- %HOMEPATH%\Desktop\Turkce Sohbet.lnk
- %PROGRAM_FILES%\detayarama\detayarama\Uninstall.ini
- %PROGRAM_FILES%\detayarama\detayarama\sbt.exe
- %PROGRAM_FILES%\detayarama\detayarama\Uninstall.exe
- %PROGRAM_FILES%\detayarama\detayarama\Asi_Mavi1.jpg
- %PROGRAM_FILES%\detayarama\detayarama\servers.ini
- %PROGRAM_FILES%\detayarama\detayarama\scripts\remote.ini
- %TEMP%\$inst\2.tmp
- %TEMP%\$inst\temp_0.tmp
- %PROGRAM_FILES%\detayarama\detayarama\scripts\script3.ini
- %PROGRAM_FILES%\detayarama\detayarama\Asi_Mavi.php
- %PROGRAM_FILES%\detayarama\detayarama\scripts\script1.ini
- %PROGRAM_FILES%\detayarama\detayarama\scripts\script2.ini
- %TEMP%\$inst\2.tmp
- %TEMP%\$inst\temp_0.tmp
- ClassName: '..::32' WindowName: ''
- ClassName: 'RegEdit_RegEdit' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: '..::' WindowName: ''