Trojan-Downloader.Win32.Small.xwr analysis(4)
Add date:
07/28/2008
Publishing date:
07/28/2008
Hits:
64
Total 4 pages, Current page:4, Jump to page:
|
%System32% \ mnmhgsrv.dll
%System32% \ mpwdeapi.dll
%System32% \ ngjxakin.sys
%System32% \ nhmxejkl.dll
%System32% \ onjzalit.exe
%System32% \ ozfyebyt.dll
%System32% \ pldhadwd.exe
%System32% \ pqzfajke.dll
%System32% \ pzwlaime.sys
%System32% \ qbhxaklo.sys
%System32% \ rijxbkin.dll
%System32% \ rnmxajkl.sys
%System32% \ sdjsakaq.sys
%System32% \ simyaapi.exe
%System32% \ siwdaapi.exe
%System32% \ smdsbsrv.sys
%System32% \ smmhbsrv.sys
%System32% \ snfybbyt.sys
%System32% \ spmybapi.sys
%System32% \ spwdbapi.sys
%System32% \ sqjsakaq.sys
%System32% \ stjxakin.exe
%System32% \ tjfyabyt.exe
%System32% \ vlhxaklo.sys
%System32% \ wymxajkl.sys
%System32% \ xzcsbhlp.sys
%System32% \ yxcschlp.dll
%System32% \ zptlcsys.dll
%System32% \ zxcsahlp.exe
%System32% \ zxmsewin.dll
%System32% \ zycbdime.dll
%System32% \ zywlcime.dll
%System32% \ zyzxjime.dll
(3) deletion virus increases registry item:
Deletion [HKEY_LOCAL_MACHINE \ SOFTWARE
\ Classes \ CLSID] under
{DA191DE0-AA86-4ED0-4B87-292A3D48BE99} sub-key
Deletion [HKEY_LOCAL_MACHINE \ SOFTWARE
\ Microsoft \ Windows \ CurrentVersion
\ ShellServiceObjectDelayLoad] under DesktopWin value
Other pages: : <<Prev * 1 * 2 * 3 * 4
|
Comment:

Category:
Home
>
the virus to be related