|
Der Schädling Win32/PcClient.NCR Trojaner
erstellt, bzw. ändert (falls bereits vorhanden) folgende Einträge in der systembeschreibenden Datenbasis:
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost] "pyqaxu"="pyqaxu"
- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\pyqaxu\Parameters] "ServiceDll"="%SystemRoot%\System32\<random>.fde"
- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\pyqaxu] "Description"="Microsoft .NET Framework TPM"
- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\pyqaxu] "DisplayName"="pyqaxu"
- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\pyqaxu] "ImagePath"="C:\WINDOWS\system32\SVCHOST.EXE -k pyqaxu"
-
Vollständige Liste...
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost] "pyqaxu"="pyqaxu"
- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\pyqaxu\Parameters] "ServiceDll"="%SystemRoot%\System32\<random>.fde"
- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\pyqaxu] "Description"="Microsoft .NET Framework TPM"
- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\pyqaxu] "DisplayName"="pyqaxu"
- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\pyqaxu] "ImagePath"="C:\WINDOWS\system32\SVCHOST.EXE -k pyqaxu"
- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\yyqaxuxv] "DisplayName"="yyqaxuxv"
- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\yyqaxuxv] "ImagePath"="\??\C:\WINDOWS\system32\drivers\<random>.sys"
- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\pyqaxu\Parameters] "ServiceDll"="%SystemRoot%\System32\<random>.fde"
- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\pyqaxu] "Description"="Microsoft .NET Framework TPM"
- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\pyqaxu] "DisplayName"="pyqaxu"
- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\pyqaxu] "ImagePath"="C:\WINDOWS\system32\SVCHOST.EXE -k pyqaxu"
- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\yyqaxuxv] "DisplayName"="yyqaxuxv"
- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\yyqaxuxv] "ImagePath"="\??\C:\WINDOWS\system32\drivers\<random>.sys"
-
zurück...
|