Keyword: au
104705 Total Search   |   Showing Results : 481 - 500
\ Advanced ShowSuperHidden = "0" HKEY_LOCAL_MACHINE\SOFTWARE\Policies\ Microsoft\Windows\WindowsUpdate\ AU NoAutoUpdate = "1" HKEY_CURRENT_USER\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\ InprocServer32
"0" HKEY_LOCAL_MACHINE\SOFTWARE\Policies\ Microsoft\Windows\WindowsUpdate\ AU NoAutoUpdate = "1" HKEY_CURRENT_USER\Software\VB and VBA Program Settings\ x\z k = "5/31/2012" HKEY_CURRENT_USER\clsid\
"0" HKEY_LOCAL_MACHINE\SOFTWARE\Policies\ Microsoft\Windows\WindowsUpdate\ AU NoAutoUpdate = "1" HKEY_CURRENT_USER\Software\VB and VBA Program Settings\ x\z k = "05-28-2012" HKEY_CURRENT_USER\clsid\
entries: HKEY_CURRENT_USER\Software\Microsoft\ Windows\CurrentVersion\Explorer\ Advanced ShowSuperHidden = "0" HKEY_LOCAL_MACHINE\SOFTWARE\Policies\ Microsoft\Windows\WindowsUpdate\ AU NoAutoUpdate = "1
\ Microsoft\Windows\WindowsUpdate\ AU NoAutoUpdate = "1" HKEY_CURRENT_USER\Software\VB and VBA Program Settings\ x\z k = "6/4/2012" HKEY_CURRENT_USER\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\ InprocServer32
entries: HKEY_CURRENT_USER\Software\Microsoft\ Windows\CurrentVersion\Explorer\ Advanced ShowSuperHidden = "0" HKEY_LOCAL_MACHINE\SOFTWARE\Policies\ Microsoft\Windows\WindowsUpdate\ AU NoAutoUpdate = "1
\WindowsUpdate\ AU NoAutoUpdate = "1" Other Details This Trojan connects to the following possibly malicious URL: http://howdy.{BLOCKED}n.com:60077/b.php This report is generated via an automated analysis system.
registry entries: HKEY_CURRENT_USER\Software\Microsoft\ Windows\CurrentVersion\Explorer\ Advanced ShowSuperHidden = "0" HKEY_LOCAL_MACHINE\SOFTWARE\Policies\ Microsoft\Windows\WindowsUpdate\ AU NoAutoUpdate
\CurrentVersion\Explorer\ Advanced ShowSuperHidden = "0" HKEY_LOCAL_MACHINE\SOFTWARE\Policies\ Microsoft\Windows\WindowsUpdate\ AU NoAutoUpdate = "1" HKEY_CURRENT_USER\Software\Microsoft\ DirectInput
\ Microsoft\Windows\WindowsUpdate\ AU NoAutoUpdate = "1" HKEY_CURRENT_USER\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\ InprocServer32 ThreadingModel = "Both" Dropping Routine This worm drops the following
\SOFTWARE\Policies\ Microsoft\Windows\WindowsUpdate\ AU NoAutoUpdate = "1" Dropping Routine This worm drops the following files: %User Profile%\html.html (Note: %User Profile% is the current user's profile
MostRecentStart = "{random values}" HKEY_CURRENT_USER\Software\Microsoft\ Windows\CurrentVersion\Explorer\ Advanced ShowSuperHidden = "0" HKEY_LOCAL_MACHINE\SOFTWARE\Policies\ Microsoft\Windows\WindowsUpdate\ AU
HKEY_CURRENT_USER\Software\Microsoft\ Windows\CurrentVersion\Explorer\ Advanced ShowSuperHidden = "0" HKEY_LOCAL_MACHINE\SOFTWARE\Policies\ Microsoft\Windows\WindowsUpdate\ AU NoAutoUpdate = "1" HKEY_CURRENT_USER
" HKEY_LOCAL_MACHINE\SOFTWARE\Policies\ Microsoft\Windows\WindowsUpdate\ AU NoAutoUpdate = "1" HKEY_CURRENT_USER\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\ InprocServer32 ThreadingModel = "Both" Dropping Routine This
\Policies\ Microsoft\Windows\WindowsUpdate\ AU NoAutoUpdate = "1" HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\ Services\.i8042prt Type = "1" HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\ Services\.i8042prt Start = "3
\SOFTWARE\Policies\ Microsoft\Windows\WindowsUpdate\ AU NoAutoUpdate = "1" It modifies the following registry entries to hide files with Hidden attributes: HKEY_CURRENT_USER\Software\Microsoft\ Windows
name}.exe /{random character}" Other System Modifications This worm adds the following registry entries: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\ Microsoft\Windows\WindowsUpdate\ AU NoAutoUpdate = "1" It
HKEY_CURRENT_USER\Software\Microsoft\ Windows\CurrentVersion\Explorer\ Advanced ShowSuperHidden = "0" HKEY_LOCAL_MACHINE\SOFTWARE\Policies\ Microsoft\Windows\WindowsUpdate\ AU NoAutoUpdate = "1" HKEY_CURRENT_USER
" HKEY_LOCAL_MACHINE\SOFTWARE\Policies\ Microsoft\Windows\WindowsUpdate\ AU NoAutoUpdate = "1" HKEY_CURRENT_USER\Software\Microsoft\ DirectInput\MostRecentApplication Name = "MPBAN.EXE" HKEY_CURRENT_USER\Software
entries as part of its installation routine: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\ Microsoft\Windows\WindowsUpdate\ AU NoAutoUpdate = "1" It modifies the following registry entries to hide files with Hidden