|
A rendszerleíró adatbázisba a(z)
[ HKEY_LOCAL_MACHINE\ SOFTWARE\ Microsoft\ Windows\ CurrentVersion\ Run] " ICQ Net" =" C: \ WINDOWS\ winlogon. exe - stealth" >
bejegyzést teszi, illetve módosítja (ha már létezik).
A Win32/Netsky.D féreg
a rendszerleíró adatbázisból az alábbi bejegyzéseket törli:
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Taskmon"
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Explorer"
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "KasperskyAv"
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "service"
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "msgsvr32"
-
teljes lista...
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Taskmon"
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Explorer"
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "KasperskyAv"
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "service"
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "msgsvr32"
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "WksPatch"
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "system."
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "DELETE ME"
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sentry"
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Windows Services Host"
- [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "Taskmon"
- [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "Explorer"
- [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "KasperskyAv"
- [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "d3dupdate.exe"
- [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "au.exe"
- [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "PINF"
- [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "OLE"
- [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "Windows Services Host"
- [HKEY_CLASSES_ROOT\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}] "InProcServer32"
-
vissza...
|