|
A Win32/Adware.180Solutions.2 trójai
a rendszerleíró adatbázisba az alábbi bejegyzéseket hozza létre, illetve módosítja (ha már létezik):
- [HKEY_LOCALE_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "HbTools"="C:\Program Files\HbTools\Bin\4.8.4.0\HbtOEAddOn.exe"
- [HKEY_LOCALE_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "WeatherOnTray"="C:\Program Files\HbTools\Bin\4.8.4.0\HbtWeatherOnTray.exe"
- [HKEY_LOCALE_MACHINE\SYSTEM\Controlset001\Control\Session Manager] "PendingFileRenameOperation"="\??\C:\DOCUME~1\VIRUST~1\LOCALS~1\Temp\nsr5.tmp\TVEngineCommand.dll"
- [HKEY_LOCALE_MACHINE\SYSTEM\Controlset001\Control\Session Manager] "PendingFileRenameOperation"="\??\C:\DOCUME~1\VIRUST~1\LOCALS~1\Temp\nsr5.tmp\System.dll"
- [HKEY_LOCALE_MACHINE\SYSTEM\Controlset001\Control\Session Manager] "PendingFileRenameOperation"="\??\C:\DOCUME~1\VIRUST~1\LOCALS~1\Temp\nsr5.tmp\"
-
teljes lista...
- [HKEY_LOCALE_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "HbTools"="C:\Program Files\HbTools\Bin\4.8.4.0\HbtOEAddOn.exe"
- [HKEY_LOCALE_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "WeatherOnTray"="C:\Program Files\HbTools\Bin\4.8.4.0\HbtWeatherOnTray.exe"
- [HKEY_LOCALE_MACHINE\SYSTEM\Controlset001\Control\Session Manager] "PendingFileRenameOperation"="\??\C:\DOCUME~1\VIRUST~1\LOCALS~1\Temp\nsr5.tmp\TVEngineCommand.dll"
- [HKEY_LOCALE_MACHINE\SYSTEM\Controlset001\Control\Session Manager] "PendingFileRenameOperation"="\??\C:\DOCUME~1\VIRUST~1\LOCALS~1\Temp\nsr5.tmp\System.dll"
- [HKEY_LOCALE_MACHINE\SYSTEM\Controlset001\Control\Session Manager] "PendingFileRenameOperation"="\??\C:\DOCUME~1\VIRUST~1\LOCALS~1\Temp\nsr5.tmp\"
- [HKEY_LOCALE_MACHINE\SYSTEM\Controlset001\Control\Session Manager] "PendingFileRenameOperation"="\??\C:\DOCUME~1\VIRUST~1\LOCALS~1\Temp\nse5.tmp\TVEngineCommand.dll"
- [HKEY_LOCALE_MACHINE\SYSTEM\Controlset001\Control\Session Manager] "PendingFileRenameOperation"="\??\C:\DOCUME~1\VIRUST~1\LOCALS~1\Temp\nse5.tmp\System.dll"
- [HKEY_LOCALE_MACHINE\SYSTEM\Controlset001\Control\Session Manager] "PendingFileRenameOperation"="\??\C:\DOCUME~1\VIRUST~1\LOCALS~1\Temp\nsg7c.tmp\"
- [HKEY_LOCALE_MACHINE\SYSTEM\Controlset001\Control\Session Manager] "PendingFileRenameOperation"="\??\C:\DOCUME~1\VIRUST~1\LOCALS~1\Temp\nsg7c.tmp\TVEngineCommand.dll"
- [HKEY_LOCALE_MACHINE\SYSTEM\Controlset001\Control\Session Manager] "PendingFileRenameOperation"="\??\C:\DOCUME~1\VIRUST~1\LOCALS~1\Temp\nsg7c.tmp\System.dll"
- [HKEY_LOCALE_MACHINE\SYSTEM\Controlset001\Control\Session Manager] "PendingFileRenameOperation"="\??\Documents and Settings\All Users\Desktop\Free PC WallPapers.lnk"
- [HKEY_LOCALE_MACHINE\SYSTEM\Controlset001\Control\Session Manager] "PendingFileRenameOperation"="\??\Documents and Settings\All Users\Desktop\Play Games.lnk"
- [HKEY_LOCALE_MACHINE\SYSTEM\Controlset001\Control\Session Manager] "PendingFileRenameOperation"="\??\C:\WINDOWS\System32\Hbinst.exe"
- [HKEY_LOCALE_MACHINE\SYSTEM\Controlset001\Control\Session Manager] "PendingFileRenameOperation"="\??\C:\Program Files\Hbtools\HBTV\HBTVHelper.dll"
- [HKEY_LOCALE_MACHINE\SYSTEM\Controlset001\Control\Session Manager] "PendingFileRenameOperation"="\??\C:\Program Files\Hbtools\Bin\4.8.0.0\HbHostOE.dll"
-
vissza...
A Win32/Adware.180Solutions.2 trójai
a rendszerleíró adatbázisba az alábbi helyeken véletlenszerű tartalommal hoz létre bejegyzéseket:
- [HKEY_LOCALE_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
- [HKEY_LOCALE_MACHINE\SYSTEM\Controlset001\Control\Session Manager]"\??\C:\WINDOWS\System32\]
- [HKEY_LOCALE_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
- [HKEY_LOCALE_MACHINE\SYSTEM\Controlset001\Control\Session Manager]"\??\C:\WINDOWS\System32\]
|