PUP. SoSoIm
*Registry path
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SoSoIm3
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SoSoIm4
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SoSoIm5
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SoSoIm6
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CfHelper33
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CfHelper44
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CfHelper55
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CfHelper66
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Microsoft Antimalware\Exclusions\Paths:C\Users\MSUser.Default\Help_4\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Microsoft Antimalware\Exclusions\Paths:C\Users\MSUser.Default\Help_5\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Microsoft Antimalware\Exclusions\Paths:C\Users\MSUser.Default\Help_6\
* Files path
C\Users\MSUser.Default\Help_6\CfHelp66.exe
C\Users\MSUser.Default\Help_5\CfHelp55.exe
C\Users\MSUser.Default\Help_4\CfHelp44.exe
C\Users\MSUser.Default\Help_3\CfHelp33.exe
c:\program files\SoSoIm_6\SoSoIm6.exe
c:\program files\SoSoIm_5\SoSoIm5.exe
c:\program files\SoSoIm_4\SoSoIm4.exe
c:\program files\SoSoIm_3\SoSoIm3.exe
|
|