2016.04.22 17:25

[Trojan] KGBKeyLogger

조회 수 398 추천 수 0 댓글 0
?

단축키

Prev이전 문서

Next다음 문서

크게 작게 위로 아래로 댓글로 가기 인쇄

Trojan.KeyLogger

 

* path

 

C^Program Files^KGB\unins000.exe
C^Program Files^KGB\ssleay32.dll
C^Program Files^KGB\sqlite3.dll
C^Program Files^KGB\MPKView.exe
C^Program Files^KGB\MPK64.exe
C^Program Files^KGB\Mpk64.dll
C^Program Files^KGB\MPK.exe
C^Program Files^KGB\Mpk.dll
C^Program Files^KGB\libeay32.dll

 

* delete key

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\mpkreg
HKEY_LOCAL_MACHINE\SOFTWARE\KGB Software
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8D319D38-B681-40FA-8063-3F50116B4E34}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\CreateExplorerShellUnelevatedTask

 

* delete value


HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run | Mpk.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers | C:\Program Files\KGB\Mpk.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers | C:\Program Files\KGB\MpkView.exe