Техническая информация
- [<HKLM>\SOFTWARE\Classes\irc\Shell\open\command] '' = '"%PROGRAM_FILES%\detay\detay\sbt.exe" -noconnect'
- [<HKLM>\SOFTWARE\Classes\ChatFile\Shell\open\command] '' = '"%PROGRAM_FILES%\detay\detay\sbt.exe" -noconnect'
- %PROGRAM_FILES%\detay\detay\sbt.exe
- %WINDIR%\msagent\agentsvr.exe -Embedding
- %WINDIR%\regedit.exe /S Asi_Mavi.php
- %PROGRAM_FILES%\detay\detay\mirc.ini
- %PROGRAM_FILES%\detay\detay\popups.ini
- %PROGRAM_FILES%\detay\detay\Asi_Mavi2.jpg
- %PROGRAM_FILES%\detay\detay\Asi_Mavi.php
- %HOMEPATH%\Desktop\Turkзe Sohbet.lnk
- %PROGRAM_FILES%\detay\detay\Uninstall.ini
- %PROGRAM_FILES%\detay\detay\remote3.ttf
- %PROGRAM_FILES%\detay\detay\Uninstall.exe
- %PROGRAM_FILES%\detay\detay\Asi_Mavi1.jpg
- %PROGRAM_FILES%\detay\detay\sbt.exe
- %PROGRAM_FILES%\detay\detay\servers.ini
- %TEMP%\$inst\2.tmp
- %TEMP%\$inst\temp_0.tmp
- %PROGRAM_FILES%\detay\detay\scripts\script2.ini
- %PROGRAM_FILES%\detay\detay\scripts\script3.ini
- %PROGRAM_FILES%\detay\detay\scripts\remote.ini
- %PROGRAM_FILES%\detay\detay\scripts\script1.ini
- %TEMP%\$inst\2.tmp
- %TEMP%\$inst\temp_0.tmp
- ClassName: '..::32' WindowName: ''
- ClassName: 'RegEdit_RegEdit' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: '..::' WindowName: ''