|
Der Schädling Win32/Adware.Apropos Trojaner
erstellt, bzw. ändert (falls bereits vorhanden) folgende Einträge in der systembeschreibenden Datenbasis:
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "AutoLoaderAproposClient"="\"C:\july14_loader.exe\" /HideUninstall /PC=\"POP.WILD_EU\" /ShowLegalNote=nonbranded"
- [HKEY_LOCAL_MACHINE\SOFTWARE\AutoLoader\AproposClient] "Attempts"
- [HKEY_LOCAL_MACHINE\SOFTWARE\AutoLoader\AproposClient] "Downloaded"
- [HKEY_LOCAL_MACHINE\SOFTWARE\AutoLoader\AproposClient] "LoadUrl"="http://download.adintelligence.net/apropos/client/POP.WILD_EU/<<try>>/AproposClientInstaller.exe"
- [HKEY_LOCAL_MACHINE\SOFTWARE\AutoLoader\AproposClient] "Parameters"="/HideUninstall /PC=\"POP.WILD_EU\" /ShowLegalNote=nonbranded"
-
Vollständige Liste...
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "AutoLoaderAproposClient"="\"C:\july14_loader.exe\" /HideUninstall /PC=\"POP.WILD_EU\" /ShowLegalNote=nonbranded"
- [HKEY_LOCAL_MACHINE\SOFTWARE\AutoLoader\AproposClient] "Attempts"
- [HKEY_LOCAL_MACHINE\SOFTWARE\AutoLoader\AproposClient] "Downloaded"
- [HKEY_LOCAL_MACHINE\SOFTWARE\AutoLoader\AproposClient] "LoadUrl"="http://download.adintelligence.net/apropos/client/POP.WILD_EU/<<try>>/AproposClientInstaller.exe"
- [HKEY_LOCAL_MACHINE\SOFTWARE\AutoLoader\AproposClient] "Parameters"="/HideUninstall /PC=\"POP.WILD_EU\" /ShowLegalNote=nonbranded"
- [HKEY_LOCAL_MACHINE\SOFTWARE\AutoLoader\AproposClient] "TempFile"="C:\DOCUME~1\tester\LOCALS~1\Temp\auf0.exe"
- [HKEY_LOCAL_MACHINE\SOFTWARE\AutoLoader\AproposClient] "Total"
- [HKEY_LOCAL_MACHINE\SOFTWARE\AutoLoader\AproposClient] "Trust"
-
zurück...
|