|
Der Schädling Win32/Obfuscated.A1 kopiert sich unter dem Namen:
fordisodata\
in das Verzeichnis von C:\Program Files.
Der Schädling Win32/Obfuscated.A1 Trojaner
erzeugt folgende Dateien:
- C:\Documents and Settings\<user>\Application Data\fordisodata\
- C:\Documents and Settings\<user>\Application Data\fordisodata\0
- C:\Documents and Settings\<user>\Application Data\fordisodata\barbtraycitycake.exe
- C:\Documents and Settings\<user>\Application Data\fordisodata\Bold2.exe
- C:\Documents and Settings\<user>\Application Data\fordisodata\name great wma.exe
- C:\Documents and Settings\<user>\Application Data\fordisodata\ozdgdxgd.exe
- C:\Documents and Settings\<user>\Application Data\fordisodata\
- C:\Documents and Settings\<user>\Application Data\fordisodata\0
- C:\Documents and Settings\<user>\Application Data\fordisodata\barbtraycitycake.exe
- C:\Documents and Settings\<user>\Application Data\fordisodata\Bold2.exe
- C:\Documents and Settings\<user>\Application Data\fordisodata\name great wma.exe
- C:\Documents and Settings\<user>\Application Data\fordisodata\ozdgdxgd.exe
|