Technical Information
- %APPDATA%\microsoft\windows\start menu\programs\startup\mshost.exe
- %TEMP%\ixp000.tmp\_setup.bat
- %TEMP%\ixp000.tmp\sultan1.aiv
- %TEMP%\ixp000.tmp\snake1.aiv
- %TEMP%\ixp000.tmp\sheriff1.aiv
- %TEMP%\ixp000.tmp\saladin1.aiv
- %TEMP%\ixp000.tmp\richard1.aiv
- %TEMP%\ixp000.tmp\rat1.aiv
- %TEMP%\ixp000.tmp\pig1.aiv
- %TEMP%\ixp000.tmp\phillip1.aiv
- %TEMP%\ixp000.tmp\nizar1.aiv
- %TEMP%\ixp000.tmp\marshal1.aiv
- %TEMP%\ixp000.tmp\freder~1.aiv
- %TEMP%\ixp000.tmp\emir1.aiv
- %TEMP%\ixp000.tmp\caliph1.aiv
- %TEMP%\ixp000.tmp\abbot1.aiv
- %TEMP%\ixp000.tmp\mshost.exe
- %TEMP%\ixp000.tmp\wazir1.aiv
- %TEMP%\ixp000.tmp\wolf1.aiv
- '90.##6.63.29':14510
- '%TEMP%\ixp000.tmp\mshost.exe'
- '<SYSTEM32>\cmd.exe' /c _setup.bat