|
Der Schädling Win32/Mebroot.K Trojaner
erstellt, bzw. ändert (falls bereits vorhanden) folgende Einträge in der systembeschreibenden Datenbasis:
- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{DEF85C80-216A-43ab-AF70-1665EDBE2780}\Security] "Security"=hex:01 00 14 80 90 00 00 00 9C 00 00 00 14 00 00 00 30 00 00 00 02 00 1C 00 01 00 00 00 02 80 14 00 FF 01 0F 00 01 01 00 00 00 00 00 01 00 00 00 00 02 00 60 00 04 00 00 00 00 00 14 00 FD 01 02 00 01 01 00 00 00 00 00 05 12 00 00 00 00 00 18 00 FF 01 0F 00 01 02 00 00 00 00 00 05 20 00 00 00 20 02 00 00 00 00 14 00 8D 01 02 00 01 01 00 00 00 00 00 05 0B 00 00 00 00 00 18 00 FD 01 02 00 01 02 00 00 00 00 00 05 20 00 00 00 23 02 00 00 01 01 00 00 00 00 00 05 12 00 00 00 01 01 00 00 00 00 00 05 12 00 00 00
- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{DEF85C80-216A-43ab-AF70-1665EDBE2780}] "ErrorControl"=0x00000000
- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{DEF85C80-216A-43ab-AF70-1665EDBE2780}] "ImagePath"="\??\C:\WINDOWS\TEMP\<number>.tmp"
- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{DEF85C80-216A-43ab-AF70-1665EDBE2780}] "Start"=0x00000003
- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{DEF85C80-216A-43ab-AF70-1665EDBE2780}] "Type"=0x00000001
-
Vollständige Liste...
- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{DEF85C80-216A-43ab-AF70-1665EDBE2780}\Security] "Security"=hex:01 00 14 80 90 00 00 00 9C 00 00 00 14 00 00 00 30 00 00 00 02 00 1C 00 01 00 00 00 02 80 14 00 FF 01 0F 00 01 01 00 00 00 00 00 01 00 00 00 00 02 00 60 00 04 00 00 00 00 00 14 00 FD 01 02 00 01 01 00 00 00 00 00 05 12 00 00 00 00 00 18 00 FF 01 0F 00 01 02 00 00 00 00 00 05 20 00 00 00 20 02 00 00 00 00 14 00 8D 01 02 00 01 01 00 00 00 00 00 05 0B 00 00 00 00 00 18 00 FD 01 02 00 01 02 00 00 00 00 00 05 20 00 00 00 23 02 00 00 01 01 00 00 00 00 00 05 12 00 00 00 01 01 00 00 00 00 00 05 12 00 00 00
- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{DEF85C80-216A-43ab-AF70-1665EDBE2780}] "ErrorControl"=0x00000000
- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{DEF85C80-216A-43ab-AF70-1665EDBE2780}] "ImagePath"="\??\C:\WINDOWS\TEMP\<number>.tmp"
- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{DEF85C80-216A-43ab-AF70-1665EDBE2780}] "Start"=0x00000003
- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{DEF85C80-216A-43ab-AF70-1665EDBE2780}] "Type"=0x00000001
- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\{DEF85C80-216A-43ab-AF70-1665EDBE2780}\Security] "Security"=hex:01 00 14 80 90 00 00 00 9C 00 00 00 14 00 00 00 30 00 00 00 02 00 1C 00 01 00 00 00 02 80 14 00 FF 01 0F 00 01 01 00 00 00 00 00 01 00 00 00 00 02 00 60 00 04 00 00 00 00 00 14 00 FD 01 02 00 01 01 00 00 00 00 00 05 12 00 00 00 00 00 18 00 FF 01 0F 00 01 02 00 00 00 00 00 05 20 00 00 00 20 02 00 00 00 00 14 00 8D 01 02 00 01 01 00 00 00 00 00 05 0B 00 00 00 00 00 18 00 FD 01 02 00 01 02 00 00 00 00 00 05 20 00 00 00 23 02 00 00 01 01 00 00 00 00 00 05 12 00 00 00 01 01 00 00 00 00 00 05 12 00 00 00
- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\{DEF85C80-216A-43ab-AF70-1665EDBE2780}] "ErrorControl"=0x00000000
- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\{DEF85C80-216A-43ab-AF70-1665EDBE2780}] "ImagePath"="\??\C:\WINDOWS\TEMP\<number>.tmp"
- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\{DEF85C80-216A-43ab-AF70-1665EDBE2780}] "Start"=0x00000003
- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\{DEF85C80-216A-43ab-AF70-1665EDBE2780}] "Type"=0x00000001
- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager] "PendingFileRenameOperations"="\??\<actualdrive>:\<actualdir>\<actualfile>"
- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_{DEF85C80-216A-43AB-AF70-1665EDBE2780}\0000] "Capabilities"=0x00000000
- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_{DEF85C80-216A-43AB-AF70-1665EDBE2780}\0000] "Class"="LegacyDriver"
- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_{DEF85C80-216A-43AB-AF70-1665EDBE2780}\0000] "ClassGUID"="{8ECC055D-047F-11D1-A537-0000F8753ED1}"
- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_{DEF85C80-216A-43AB-AF70-1665EDBE2780}\0000] "ConfigFlags"=0x00000000
- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_{DEF85C80-216A-43AB-AF70-1665EDBE2780}\0000] "DeviceDesc"="{DEF85C80-216A-43ab-AF70-1665EDBE2780}"
- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_{DEF85C80-216A-43AB-AF70-1665EDBE2780}\0000] "Legacy"=0x00000001
- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_{DEF85C80-216A-43AB-AF70-1665EDBE2780}\0000] "Service"="{DEF85C80-216A-43ab-AF70-1665EDBE2780}"
- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_{DEF85C80-216A-43AB-AF70-1665EDBE2780}] "NextInstance"=0x00000001
- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_{DEF85C80-216A-43AB-AF70-1665EDBE2780}\0000] "Capabilities"=0x00000000
- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_{DEF85C80-216A-43AB-AF70-1665EDBE2780}\0000] "Class"="LegacyDriver"
- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_{DEF85C80-216A-43AB-AF70-1665EDBE2780}\0000] "ClassGUID"="{8ECC055D-047F-11D1-A537-0000F8753ED1}"
- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_{DEF85C80-216A-43AB-AF70-1665EDBE2780}\0000] "ConfigFlags"=0x00000000
- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_{DEF85C80-216A-43AB-AF70-1665EDBE2780}\0000] "DeviceDesc"="{DEF85C80-216A-43ab-AF70-1665EDBE2780}"
- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_{DEF85C80-216A-43AB-AF70-1665EDBE2780}\0000] "Legacy"=0x00000001
- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_{DEF85C80-216A-43AB-AF70-1665EDBE2780}\0000] "Service"="{DEF85C80-216A-43ab-AF70-1665EDBE2780}"
- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_{DEF85C80-216A-43AB-AF70-1665EDBE2780}] "NextInstance"=0x00000001
-
zurück...
|