Trojan.KaZaA

by ezclean posted Mar 19, 2021
?

단축키

Prev이전 문서

Next다음 문서

ESC닫기

크게 작게 위로 아래로 댓글로 가기 인쇄

Trojan.KaZaA

*file
C:\Windows\Installer\363d04.msi
C:\Users\{USERNAME}\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Kazaalite\Speed Up.lnk
C:\Users\{USERNAME}\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Kazaalite\Sig2Dat.lnk
C:\Users\{USERNAME}\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Kazaalite\Kazaalite.lnk
C:\Users\{USERNAME}\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Kazaalite\Kazaalite.com Support Forums.lnk
C:\Users\{USERNAME}\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Kazaalite\Kazaalite.com HomePage.lnk
C:\Users\{USERNAME}\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Kazaalite\Dat Viewer.lnk
C:\Users\{USERNAME}\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Kazaalite\AVI Preview.lnk
C:\Program Files\KaZaA Lite\web\start.htm
C:\Program Files\KaZaA Lite\web\go.gif
C:\Program Files\KaZaA Lite\unins000.exe
C:\Program Files\KaZaA Lite\unins000.dat
C:\Program Files\KaZaA Lite\TopSearch.dll
C:\Program Files\KaZaA Lite\Speed Up.exe
C:\Program Files\KaZaA Lite\sig2dat.exe
C:\Program Files\KaZaA Lite\shared.ico
C:\Program Files\KaZaA Lite\libfn.dll
C:\Program Files\KaZaA Lite\kzscan.dll
C:\Program Files\KaZaA Lite\kazaahelp.chm
C:\Program Files\KaZaA Lite\Kazaa.exe
C:\Program Files\KaZaA Lite\help.ico
C:\Program Files\KaZaA Lite\dat_view.exe
C:\Program Files\KaZaA Lite\cd_clint.dll
C:\Program Files\KaZaA Lite\bdupd.dll
C:\Program Files\KaZaA Lite\bdcore.dll
C:\Program Files\KaZaA Lite\AVIPreview.exe
C:\Program Files\Common Files\Wise Installation Wizard\WIS4574B9B383144C0F88634796CC739CEF_2_0_2_1.


*reg_key
HKEY_CURRENT_USER\SOFTWARE\Wise Solutions
HKEY_CURRENT_USER\SOFTWARE\Classes\sig2dat
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Products\3B9B47544138F0C488367469CC37C9FE
HKLM\SOFTWARE\KaZaA
HKLM\SOFTWARE\Sig2dat
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2893608250-2205728168-3091723128-1001\Products\3B9B47544138F0C488367469CC37C9FE
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4574B9B3-8314-4C0F-8863-4796CC739CEF}
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\kazaalite202_is1

11111.png