Trojan.KeyLogger
* path
C^Program Files^KGB\unins000.exe
C^Program Files^KGB\ssleay32.dll
C^Program Files^KGB\sqlite3.dll
C^Program Files^KGB\MPKView.exe
C^Program Files^KGB\MPK64.exe
C^Program Files^KGB\Mpk64.dll
C^Program Files^KGB\MPK.exe
C^Program Files^KGB\Mpk.dll
C^Program Files^KGB\libeay32.dll
* delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\mpkreg
HKEY_LOCAL_MACHINE\SOFTWARE\KGB Software
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8D319D38-B681-40FA-8063-3F50116B4E34}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\CreateExplorerShellUnelevatedTask
* delete value
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run | Mpk.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers | C:\Program Files\KGB\Mpk.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers | C:\Program Files\KGB\MpkView.exe
|
|