|
Der Schädling erstellt, bzw. ändert (falls bereits vorhanden) folgenden Eintrag in der systembeschreibenden Datenbasis:
[ HKEY_LOCAL_MACHINE\ SOFTWARE\ Microsoft\ Windows\ CurrentVersion\ Run] " Tiny AV" =" C: \ WINDOWS\ fooding. exe - antivirus service" >
Der Wurm Win32/Netsky.I löscht folgende Einträge aus der Registry:
- HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Taskmon
- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Taskmon
- HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Explorer
- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Explorer
- HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\KasperskyAv
-
Vollständige Liste...
- HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Taskmon
- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Taskmon
- HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Explorer
- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Explorer
- HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\KasperskyAv
- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\KasperskyAv
- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\msgsvr32
- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\DELETE ME
- HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\d3dupdate.exe
- HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\au.exe
- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\service
- HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OLE
- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Sentry
- HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\PINF
- HKLM\System\CurrentControlSet\Services\WksPatch
- HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Windows Services Host
- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Windows Services Host
- HKCR\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\InProcServer32
- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\system
- HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\gouday.exe
- HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\rate.exe
- HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\srate.exe
- HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\sysmon.exe
- HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ssate.exe
-
zurück...
|