Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '' = '%PROGRAM_FILES%\shayan-cracker\Nhspy Server.exe'
- %PROGRAM_FILES%\shayan-cracker\Nhspy Server.exe
- YahooMessenger.exe
- firefox.exe
- %PROGRAM_FILES%\shayan-cracker\msvbvm60.dll
- %PROGRAM_FILES%\shayan-cracker\msado20.tlb
- %PROGRAM_FILES%\shayan-cracker\Comdlg32.ocx
- %PROGRAM_FILES%\shayan-cracker\oleaut32.dll
- %PROGRAM_FILES%\shayan-cracker\SETUP1.EXE
- %PROGRAM_FILES%\shayan-cracker\password.txt
- %PROGRAM_FILES%\shayan-cracker\olepro32.dll
- %PROGRAM_FILES%\shayan-cracker\COMCAT.DLL
- %PROGRAM_FILES%\shayan-cracker\stdole2.tlb
- %PROGRAM_FILES%\shayan-cracker\ST6UNST.EXE
- %PROGRAM_FILES%\shayan-cracker\shayan-cracker.exe
- %PROGRAM_FILES%\shayan-cracker\VB6STKIT.DLL
- %PROGRAM_FILES%\shayan-cracker\asycfilt.dll
- %PROGRAM_FILES%\shayan-cracker\PDataBass.xml
- %PROGRAM_FILES%\shayan-cracker\Nhspy Server.exe
- 'op#####e.nimbuzz.com':5222
- DNS ASK op#####e.nimbuzz.com
- ClassName: 'Indicator' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'EDIT' WindowName: ''