PE_SALITY.M
Virus:Win32/Sality.AM (Microsoft); Spam-Mailbot (McAfee); W32.Sality.AE (Symantec); Virus.Win32.Sality.aa (Kaspersky); Virus.Win32.Sality.am (v) (Sunbelt); Win32.Sality.2.NX (FSecure)
Windows 2000, Windows XP, Windows Server 2003

マルウェアタイプ:
ファイル感染型
破壊活動の有無:
なし
暗号化:
感染報告の有無 :
はい
概要
ウイルスは、他のマルウェアに作成されるか、悪意あるWebサイトからユーザが誤ってダウンロードすることによりコンピュータに侵入します。
詳細
侵入方法
ウイルスは、他のマルウェアに作成されるか、悪意あるWebサイトからユーザが誤ってダウンロードすることによりコンピュータに侵入します。
他のシステム変更
ウイルスは、以下のレジストリキーを追加します。
HKEY_CURRENT_USER\Software\Administrator914\
-993627007
ウイルスは、以下のレジストリ値を追加します。
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Services\SharedAccess\Parameters\
FirewallPolicy\StandardProfile\AuthorizedApplications\
List
{malware path and file name} = "{malware path and file name}:*:enabled:ipsec"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Internet Settings
GlobalUserOffline = "0"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\policies\
system
EnableLUA = "0"
HKEY_CURRENT_USER\Software\Administrator914\
-993627007
1768776769 = "4"
HKEY_CURRENT_USER\Software\Administrator914\
-993627007
-757413758 = "0"
HKEY_CURRENT_USER\Software\Administrator914\
-993627007
1011363011 = "0"
HKEY_CURRENT_USER\Software\Administrator914\
-993627007
-1514827516 = "23"
HKEY_CURRENT_USER\Software\Administrator914\
-993627007
253949253 = "143"
HKEY_CURRENT_USER\Software\Administrator914\
-993627007
2022726022 = "{random characters}"
HKEY_CURRENT_USER\Software\Administrator914\
-993627007
-503464505 = "{random characters}"
HKEY_CURRENT_USER\Software\Administrator914
A1_0 = "22487345"
HKEY_CURRENT_USER\Software\Administrator914
A2_0 = "1bdc"
HKEY_CURRENT_USER\Software\Administrator914
A3_0 = "136641"
HKEY_CURRENT_USER\Software\Administrator914
A4_0 = "0"
HKEY_CURRENT_USER\Software\Administrator914
A1_1 = "b5e2111"
HKEY_CURRENT_USER\Software\Administrator914
A2_1 = "696d7a8f"
HKEY_CURRENT_USER\Software\Administrator914
A3_1 = "686e2"
HKEY_CURRENT_USER\Software\Administrator914
A4_1 = "696d6441"
HKEY_CURRENT_USER\Software\Administrator914
A1_2 = "d8186ec1"
HKEY_CURRENT_USER\Software\Administrator914
A2_2 = "d2daddc3"
HKEY_CURRENT_USER\Software\Administrator914
A3_2 = "d3d9aec3"
HKEY_CURRENT_USER\Software\Administrator914
A4_2 = "d2dac882"
HKEY_CURRENT_USER\Software\Administrator914
A1_3 = "323bd9a"
HKEY_CURRENT_USER\Software\Administrator914
A2_3 = "3c483e72"
HKEY_CURRENT_USER\Software\Administrator914
A3_3 = "3d4b4a82"
HKEY_CURRENT_USER\Software\Administrator914
A4_3 = "3c482cc3"
HKEY_CURRENT_USER\Software\Administrator914
A1_4 = "746b94"
HKEY_CURRENT_USER\Software\Administrator914
A2_4 = "a5b584f7"
HKEY_CURRENT_USER\Software\Administrator914
A3_4 = "a4b6f745"
HKEY_CURRENT_USER\Software\Administrator914
A4_4 = "a5b5914"
HKEY_CURRENT_USER\Software\Administrator914
A1_5 = "8111b15"
HKEY_CURRENT_USER\Software\Administrator914
A2_5 = "f22eb8b"
HKEY_CURRENT_USER\Software\Administrator914
A3_5 = "e21934"
HKEY_CURRENT_USER\Software\Administrator914
A4_5 = "f22f545"
HKEY_CURRENT_USER\Software\Administrator914
A1_6 = "b2a41f5f"
HKEY_CURRENT_USER\Software\Administrator914
A2_6 = "7894d3e"
HKEY_CURRENT_USER\Software\Administrator914
A3_6 = "79933fc7"
HKEY_CURRENT_USER\Software\Administrator914
A4_6 = "7895986"
HKEY_CURRENT_USER\Software\Administrator914
A1_7 = "4db919e"
HKEY_CURRENT_USER\Software\Administrator914
A2_7 = "e1fda5c1"
HKEY_CURRENT_USER\Software\Administrator914
A3_7 = "efedb86"
HKEY_CURRENT_USER\Software\Administrator914
A4_7 = "e1fdbdc7"
HKEY_CURRENT_USER\Software\Administrator914
A1_8 = "d3af51"
HKEY_CURRENT_USER\Software\Administrator914
A2_8 = "4b6b3444"
HKEY_CURRENT_USER\Software\Administrator914
A3_8 = "4a684449"
HKEY_CURRENT_USER\Software\Administrator914
A4_8 = "4b6b228"
HKEY_CURRENT_USER\Software\Administrator914
A1_9 = "ba7b6b1c"
HKEY_CURRENT_USER\Software\Administrator914
A2_9 = "b4d89ced"
HKEY_CURRENT_USER\Software\Administrator914
A3_9 = "b5dbe8"
HKEY_CURRENT_USER\Software\Administrator914
A4_9 = "b4d88649"
HKEY_CURRENT_USER\Software\Administrator914
A1_10 = "25854fd3"
HKEY_CURRENT_USER\Software\Administrator914
A2_10 = "1e45f9"
HKEY_CURRENT_USER\Software\Administrator914
A3_10 = "1f468ccb"
HKEY_CURRENT_USER\Software\Administrator914
A4_10 = "1e45ea8a"
HKEY_CURRENT_USER\Software\Administrator914
A1_11 = "6dd19386"
HKEY_CURRENT_USER\Software\Administrator914
A2_11 = "87b354bc"
HKEY_CURRENT_USER\Software\Administrator914
A3_11 = "86b288a"
HKEY_CURRENT_USER\Software\Administrator914
A4_11 = "87b34ecb"
HKEY_CURRENT_USER\Software\Administrator914
A1_12 = "1a92ed7a"
HKEY_CURRENT_USER\Software\Administrator914
A2_12 = "f12a1c8"
HKEY_CURRENT_USER\Software\Administrator914
A3_12 = "f23d54d"
HKEY_CURRENT_USER\Software\Administrator914
A4_12 = "f12b3c"
HKEY_CURRENT_USER\Software\Administrator914
A1_13 = "fcfb8117"
HKEY_CURRENT_USER\Software\Administrator914
A2_13 = "5a8e88e9"
HKEY_CURRENT_USER\Software\Administrator914
A3_13 = "5b8d71c"
HKEY_CURRENT_USER\Software\Administrator914
A4_13 = "5a8e174d"
HKEY_CURRENT_USER\Software\Administrator914
A1_14 = "49759a4d"
HKEY_CURRENT_USER\Software\Administrator914
A2_14 = "c3fb6ef2"
HKEY_CURRENT_USER\Software\Administrator914
A3_14 = "c2f81dcf"
HKEY_CURRENT_USER\Software\Administrator914
A4_14 = "c3fb7b8e"
HKEY_CURRENT_USER\Software\Administrator914
A1_15 = "8477f396"
HKEY_CURRENT_USER\Software\Administrator914
A2_15 = "2d68ffa2"
HKEY_CURRENT_USER\Software\Administrator914
A3_15 = "2c6bb98e"
HKEY_CURRENT_USER\Software\Administrator914
A4_15 = "2d68dfcf"
HKEY_CURRENT_USER\Software\Administrator914
A1_16 = "1f5d7b67"
HKEY_CURRENT_USER\Software\Administrator914
A2_16 = "96d65151"
HKEY_CURRENT_USER\Software\Administrator914
A3_16 = "97d52251"
HKEY_CURRENT_USER\Software\Administrator914
A4_16 = "96d6441"
HKEY_CURRENT_USER\Software\Administrator914
A1_17 = "e21b1484"
HKEY_CURRENT_USER\Software\Administrator914
A2_17 = "43baf9"
HKEY_CURRENT_USER\Software\Administrator914
A3_17 = "14ce1"
HKEY_CURRENT_USER\Software\Administrator914
A4_17 = "43a851"
HKEY_CURRENT_USER\Software\Administrator914
A1_18 = "66323ac6"
HKEY_CURRENT_USER\Software\Administrator914
A2_18 = "69b11a9a"
HKEY_CURRENT_USER\Software\Administrator914
A3_18 = "68b26ad3"
HKEY_CURRENT_USER\Software\Administrator914
A4_18 = "69b1c92"
HKEY_CURRENT_USER\Software\Administrator914
A1_19 = "b9121a85"
HKEY_CURRENT_USER\Software\Administrator914
A2_19 = "d31e66d7"
HKEY_CURRENT_USER\Software\Administrator914
A3_19 = "d21d1692"
HKEY_CURRENT_USER\Software\Administrator914
A4_19 = "d31e7d3"
HKEY_CURRENT_USER\Software\Administrator914
A1_20 = "7347ddd"
HKEY_CURRENT_USER\Software\Administrator914
A2_20 = "3c8bc8c1"
HKEY_CURRENT_USER\Software\Administrator914
A3_20 = "3d88b355"
HKEY_CURRENT_USER\Software\Administrator914
A4_20 = "3c8bd514"
HKEY_CURRENT_USER\Software\Administrator914
A1_21 = "6b9511c"
HKEY_CURRENT_USER\Software\Administrator914
A2_21 = "a5f92d94"
HKEY_CURRENT_USER\Software\Administrator914
A3_21 = "a4fa5f14"
HKEY_CURRENT_USER\Software\Administrator914
A4_21 = "a5f93955"
HKEY_CURRENT_USER\Software\Administrator914
A1_22 = "adb1a6ac"
HKEY_CURRENT_USER\Software\Administrator914
A2_22 = "f66882e"
HKEY_CURRENT_USER\Software\Administrator914
A3_22 = "e65fbd7"
HKEY_CURRENT_USER\Software\Administrator914
A4_22 = "f669d96"
HKEY_CURRENT_USER\Software\Administrator914
A1_23 = "6649b8a"
HKEY_CURRENT_USER\Software\Administrator914
A2_23 = "78d41429"
HKEY_CURRENT_USER\Software\Administrator914
A3_23 = "79d76796"
HKEY_CURRENT_USER\Software\Administrator914
A4_23 = "78d41d7"
HKEY_CURRENT_USER\Software\Administrator914
A1_24 = "83b16ed2"
HKEY_CURRENT_USER\Software\Administrator914
A2_24 = "e24178e5"
HKEY_CURRENT_USER\Software\Administrator914
A3_24 = "e34259"
HKEY_CURRENT_USER\Software\Administrator914
A4_24 = "e2416618"
HKEY_CURRENT_USER\Software\Administrator914
A1_25 = "1ac5e7"
HKEY_CURRENT_USER\Software\Administrator914
A2_25 = "4baed97a"
HKEY_CURRENT_USER\Software\Administrator914
A3_25 = "4aadac18"
HKEY_CURRENT_USER\Software\Administrator914
A4_25 = "4baeca59"
HKEY_CURRENT_USER\Software\Administrator914
A1_26 = "2d833c48"
HKEY_CURRENT_USER\Software\Administrator914
A2_26 = "b51c34b2"
HKEY_CURRENT_USER\Software\Administrator914
A3_26 = "b41f48db"
HKEY_CURRENT_USER\Software\Administrator914
A4_26 = "b51c2e9a"
HKEY_CURRENT_USER\Software\Administrator914
A1_27 = "45dd6b85"
HKEY_CURRENT_USER\Software\Administrator914
A2_27 = "1e898817"
HKEY_CURRENT_USER\Software\Administrator914
A3_27 = "1f8af49a"
HKEY_CURRENT_USER\Software\Administrator914
A4_27 = "1e8992db"
HKEY_CURRENT_USER\Software\Administrator914
A1_28 = "744fdc5"
HKEY_CURRENT_USER\Software\Administrator914
A2_28 = "87f6e52"
HKEY_CURRENT_USER\Software\Administrator914
A3_28 = "86f5915d"
HKEY_CURRENT_USER\Software\Administrator914
A4_28 = "87f6f71c"
HKEY_CURRENT_USER\Software\Administrator914
A1_29 = "b4552e8"
HKEY_CURRENT_USER\Software\Administrator914
A2_29 = "f164477d"
HKEY_CURRENT_USER\Software\Administrator914
A3_29 = "f673d1c"
HKEY_CURRENT_USER\Software\Administrator914
A4_29 = "f1645b5d"
HKEY_CURRENT_USER\Software\Administrator914
A1_30 = "ec58ec3"
HKEY_CURRENT_USER\Software\Administrator914
A2_30 = "5ad1a7f6"
HKEY_CURRENT_USER\Software\Administrator914
A3_30 = "5bd2d9df"
HKEY_CURRENT_USER\Software\Administrator914
A4_30 = "5ad1bf9e"
HKEY_CURRENT_USER\Software\Administrator914
A1_31 = "65d1586"
HKEY_CURRENT_USER\Software\Administrator914
A2_31 = "c43f3b26"
HKEY_CURRENT_USER\Software\Administrator914
A3_31 = "c53c459e"
HKEY_CURRENT_USER\Software\Administrator914
A4_31 = "c43f23df"
HKEY_CURRENT_USER\Software\Administrator914
A1_32 = "d2ca179"
HKEY_CURRENT_USER\Software\Administrator914
A2_32 = "2dac8698"
HKEY_CURRENT_USER\Software\Administrator914
A3_32 = "2cafee61"
HKEY_CURRENT_USER\Software\Administrator914
A4_32 = "2dac882"
HKEY_CURRENT_USER\Software\Administrator914
A1_33 = "53dff1"
HKEY_CURRENT_USER\Software\Administrator914
A2_33 = "9719f93c"
HKEY_CURRENT_USER\Software\Administrator914
A3_33 = "961a8a2"
HKEY_CURRENT_USER\Software\Administrator914
A4_33 = "9719ec61"
HKEY_CURRENT_USER\Software\Administrator914
A1_34 = "71a533d1"
HKEY_CURRENT_USER\Software\Administrator914
A2_34 = "8746a6"
HKEY_CURRENT_USER\Software\Administrator914
A3_34 = "18436e3"
HKEY_CURRENT_USER\Software\Administrator914
A4_34 = "875a2"
HKEY_CURRENT_USER\Software\Administrator914
A1_35 = "3c9f1b3"
HKEY_CURRENT_USER\Software\Administrator914
A2_35 = "69f4aed7"
HKEY_CURRENT_USER\Software\Administrator914
A3_35 = "68f7d2a2"
HKEY_CURRENT_USER\Software\Administrator914
A4_35 = "69f4b4e3"
HKEY_CURRENT_USER\Software\Administrator914
A1_36 = "3de187a"
HKEY_CURRENT_USER\Software\Administrator914
A2_36 = "d362c79"
HKEY_CURRENT_USER\Software\Administrator914
A3_36 = "d2617f65"
HKEY_CURRENT_USER\Software\Administrator914
A4_36 = "d3621924"
HKEY_CURRENT_USER\Software\Administrator914
A1_37 = "f794a33"
HKEY_CURRENT_USER\Software\Administrator914
A2_37 = "3ccf6e27"
HKEY_CURRENT_USER\Software\Administrator914
A3_37 = "3dcc1b24"
HKEY_CURRENT_USER\Software\Administrator914
A4_37 = "3ccf7d65"
HKEY_CURRENT_USER\Software\Administrator914
A1_38 = "83b7ded1"
HKEY_CURRENT_USER\Software\Administrator914
A2_38 = "a63cf4e7"
HKEY_CURRENT_USER\Software\Administrator914
A3_38 = "a73f87e7"
HKEY_CURRENT_USER\Software\Administrator914
A4_38 = "a63ce1a6"
HKEY_CURRENT_USER\Software\Administrator914
A1_39 = "cee6f5a"
HKEY_CURRENT_USER\Software\Administrator914
A2_39 = "faa53c1"
HKEY_CURRENT_USER\Software\Administrator914
A3_39 = "ea923a6"
HKEY_CURRENT_USER\Software\Administrator914
A4_39 = "faa45e7"
HKEY_CURRENT_USER\Software\Administrator914
A1_40 = "15faca66"
HKEY_CURRENT_USER\Software\Administrator914
A2_40 = "7917bf4"
HKEY_CURRENT_USER\Software\Administrator914
A3_40 = "7814cc69"
HKEY_CURRENT_USER\Software\Administrator914
A4_40 = "7917aa28"
HKEY_CURRENT_USER\Software\Administrator914
A1_41 = "82c3753"
HKEY_CURRENT_USER\Software\Administrator914
A2_41 = "e2851cf9"
HKEY_CURRENT_USER\Software\Administrator914
A3_41 = "e3866828"
HKEY_CURRENT_USER\Software\Administrator914
A4_41 = "e285e69"
HKEY_CURRENT_USER\Software\Administrator914
A1_42 = "c211c76"
HKEY_CURRENT_USER\Software\Administrator914
A2_42 = "4bf26678"
HKEY_CURRENT_USER\Software\Administrator914
A3_42 = "4af114eb"
HKEY_CURRENT_USER\Software\Administrator914
A4_42 = "4bf272aa"
HKEY_CURRENT_USER\Software\Administrator914
A1_43 = "3479c755"
HKEY_CURRENT_USER\Software\Administrator914
A2_43 = "b55fc5d3"
HKEY_CURRENT_USER\Software\Administrator914
A3_43 = "b45cbaa"
HKEY_CURRENT_USER\Software\Administrator914
A4_43 = "b55fd6eb"
HKEY_CURRENT_USER\Software\Administrator914
A1_44 = "b63795ef"
HKEY_CURRENT_USER\Software\Administrator914
A2_44 = "1ecd282"
HKEY_CURRENT_USER\Software\Administrator914
A3_44 = "1fce5d6d"
HKEY_CURRENT_USER\Software\Administrator914
A4_44 = "1ecd3b2c"
HKEY_CURRENT_USER\Software\Administrator914
A1_45 = "713d3f"
HKEY_CURRENT_USER\Software\Administrator914
A2_45 = "883a8f5"
HKEY_CURRENT_USER\Software\Administrator914
A3_45 = "8939f92c"
HKEY_CURRENT_USER\Software\Administrator914
A4_45 = "883a9f6d"
HKEY_CURRENT_USER\Software\Administrator914
A1_46 = "548471fa"
HKEY_CURRENT_USER\Software\Administrator914
A2_46 = "f1a81542"
HKEY_CURRENT_USER\Software\Administrator914
A3_46 = "fab65ef"
HKEY_CURRENT_USER\Software\Administrator914
A4_46 = "f1a83ae"
HKEY_CURRENT_USER\Software\Administrator914
A1_47 = "76c32e51"
HKEY_CURRENT_USER\Software\Administrator914
A2_47 = "5b157683"
HKEY_CURRENT_USER\Software\Administrator914
A3_47 = "5a161ae"
HKEY_CURRENT_USER\Software\Administrator914
A4_47 = "5b1567ef"
HKEY_CURRENT_USER\Software\Administrator914
A1_48 = "bcb5a46f"
HKEY_CURRENT_USER\Software\Administrator914
A2_48 = "c482da8"
HKEY_CURRENT_USER\Software\Administrator914
A3_48 = "c581aa71"
HKEY_CURRENT_USER\Software\Administrator914
A4_48 = "c482cc3"
HKEY_CURRENT_USER\Software\Administrator914
A1_49 = "9f5412c"
HKEY_CURRENT_USER\Software\Administrator914
A2_49 = "2df2d45"
HKEY_CURRENT_USER\Software\Administrator914
A3_49 = "2cf3563"
HKEY_CURRENT_USER\Software\Administrator914
A4_49 = "2df371"
HKEY_CURRENT_USER\Software\Administrator914
A1_50 = "31a8b9eb"
HKEY_CURRENT_USER\Software\Administrator914
A2_50 = "975d8af9"
HKEY_CURRENT_USER\Software\Administrator914
A3_50 = "965ef2f3"
HKEY_CURRENT_USER\Software\Administrator914
A4_50 = "975d94b2"
HKEY_CURRENT_USER\Software\Administrator914
A1_51 = "4a1a3d86"
HKEY_CURRENT_USER\Software\Administrator914
A2_51 = "cae781"
HKEY_CURRENT_USER\Software\Administrator914
A3_51 = "1c99eb2"
HKEY_CURRENT_USER\Software\Administrator914
A4_51 = "caf8f3"
HKEY_CURRENT_USER\Software\Administrator914
A1_52 = "5b892f69"
HKEY_CURRENT_USER\Software\Administrator914
A2_52 = "6a38475c"
HKEY_CURRENT_USER\Software\Administrator914
A3_52 = "6b3b3b75"
HKEY_CURRENT_USER\Software\Administrator914
A4_52 = "6a385d34"
HKEY_CURRENT_USER\Software\Administrator914
A1_53 = "5ffb124"
HKEY_CURRENT_USER\Software\Administrator914
A2_53 = "d3a5d9fd"
HKEY_CURRENT_USER\Software\Administrator914
A3_53 = "d2a6a734"
HKEY_CURRENT_USER\Software\Administrator914
A4_53 = "d3a5c175"
HKEY_CURRENT_USER\Software\Administrator914
A1_54 = "dbc9c9cd"
HKEY_CURRENT_USER\Software\Administrator914
A2_54 = "3d133866"
HKEY_CURRENT_USER\Software\Administrator914
A3_54 = "3c143f7"
HKEY_CURRENT_USER\Software\Administrator914
A4_54 = "3d1325b6"
HKEY_CURRENT_USER\Software\Administrator914
A1_55 = "af921a2"
HKEY_CURRENT_USER\Software\Administrator914
A2_55 = "a68934f"
HKEY_CURRENT_USER\Software\Administrator914
A3_55 = "a783efb6"
HKEY_CURRENT_USER\Software\Administrator914
A4_55 = "a6889f7"
HKEY_CURRENT_USER\Software\Administrator914
A1_56 = "de578775"
HKEY_CURRENT_USER\Software\Administrator914
A2_56 = "fedf796"
HKEY_CURRENT_USER\Software\Administrator914
A3_56 = "eee8879"
HKEY_CURRENT_USER\Software\Administrator914
A4_56 = "fedee38"
HKEY_CURRENT_USER\Software\Administrator914
A1_57 = "268db1"
HKEY_CURRENT_USER\Software\Administrator914
A2_57 = "795b45bc"
HKEY_CURRENT_USER\Software\Administrator914
A3_57 = "78583438"
HKEY_CURRENT_USER\Software\Administrator914
A4_57 = "795b5279"
HKEY_CURRENT_USER\Software\Administrator914
A1_58 = "317cfece"
HKEY_CURRENT_USER\Software\Administrator914
A2_58 = "e2c8a11a"
HKEY_CURRENT_USER\Software\Administrator914
A3_58 = "e3cbdfb"
HKEY_CURRENT_USER\Software\Administrator914
A4_58 = "e2c8b6ba"
ウイルスは、以下のレジストリキーを削除します。
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
AppMgmt
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
Base
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
Boot Bus Extender
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
Boot file system
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
CryptSvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
DcomLaunch
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
dmadmin
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
dmboot.sys
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
dmio.sys
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
dmload.sys
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
dmserver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
EventLog
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
File system
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
Filter
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
HelpSvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
Netlogon
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
PCI Configuration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
PlugPlay
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
PNP Filter
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
Primary disk
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
RpcSs
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
SCSI Class
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
sermouse.sys
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
sr.sys
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
SRService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
System Bus Extender
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
vga.sys
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
vgasave.sys
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
WinMgmt
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
{36FC9E60-C465-11CF-8056-444553540000}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
{4D36E965-E325-11CE-BFC1-08002BE10318}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
{4D36E967-E325-11CE-BFC1-08002BE10318}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
{4D36E969-E325-11CE-BFC1-08002BE10318}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
{4D36E96A-E325-11CE-BFC1-08002BE10318}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
{4D36E96B-E325-11CE-BFC1-08002BE10318}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
{4D36E96F-E325-11CE-BFC1-08002BE10318}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
{4D36E977-E325-11CE-BFC1-08002BE10318}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
{4D36E97B-E325-11CE-BFC1-08002BE10318}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
{4D36E97D-E325-11CE-BFC1-08002BE10318}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
{4D36E980-E325-11CE-BFC1-08002BE10318}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
{71A27CDD-812A-11D0-BEC7-08002BE2092F}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
AFD
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
AppMgmt
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
Base
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
Boot Bus Extender
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
Boot file system
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
Browser
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
CryptSvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
DcomLaunch
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
Dhcp
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
dmadmin
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
dmboot.sys
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
dmio.sys
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
dmload.sys
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
dmserver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
DnsCache
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
EventLog
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
File system
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
Filter
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
HelpSvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
ip6fw.sys
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
ipnat.sys
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
LanmanServer
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
LanmanWorkstation
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
LmHosts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
Messenger
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
NDIS
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
NDIS Wrapper
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
Ndisuio
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
NetBIOS
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
NetBIOSGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
NetBT
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
NetDDEGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
Netlogon
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
NetMan
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
Network
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
NetworkProvider
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
NtLmSsp
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
PCI Configuration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
PlugPlay
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
PNP Filter
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
PNP_TDI
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
Primary disk
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
rdpcdd.sys
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
rdpdd.sys
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
rdpwd.sys
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
rdsessmgr
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
RpcSs
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
SCSI Class
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
sermouse.sys
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
SharedAccess
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
sr.sys
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
SRService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
Streams Drivers
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
System Bus Extender
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
Tcpip
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
TDI
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
tdpipe.sys
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
tdtcp.sys
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
termservice
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
vga.sys
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
vgasave.sys
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
WinMgmt
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
WZCSVC
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
{36FC9E60-C465-11CF-8056-444553540000}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
{4D36E965-E325-11CE-BFC1-08002BE10318}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
{4D36E967-E325-11CE-BFC1-08002BE10318}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
{4D36E969-E325-11CE-BFC1-08002BE10318}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
{4D36E96A-E325-11CE-BFC1-08002BE10318}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
{4D36E96B-E325-11CE-BFC1-08002BE10318}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
{4D36E96F-E325-11CE-BFC1-08002BE10318}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
{4D36E972-E325-11CE-BFC1-08002BE10318}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
{4D36E973-E325-11CE-BFC1-08002BE10318}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
{4D36E974-E325-11CE-BFC1-08002BE10318}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
{4D36E975-E325-11CE-BFC1-08002BE10318}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
{4D36E977-E325-11CE-BFC1-08002BE10318}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
{4D36E97B-E325-11CE-BFC1-08002BE10318}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
{4D36E97D-E325-11CE-BFC1-08002BE10318}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
{4D36E980-E325-11CE-BFC1-08002BE10318}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
{71A27CDD-812A-11D0-BEC7-08002BE2092F}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network
作成活動
ウイルスは、以下のファイルを作成します。
- %User Temp%\winjbxh.exe
- %User Temp%\winepejmx.exe
- %System%\drivers\oifil.sys
- %User Temp%\winpcrm.exe
- %System Root%\9de5
- D:\a21c
- %User Temp%\wingmxe.exe
- E:\a623
- %User Temp%\winedbv.exe
- F:\aa2a
- %User Temp%\winddgof.exe
- %User Temp%\winjgxc.exe
- G:\ae7f
- %User Temp%\winfkom.exe
- H:\b296
- %User Temp%\winewec.exe
- I:\b6ad
- %User Temp%\winmieot.exe
- %User Temp%\winwcypi.exe
- J:\baa5
- %User Temp%\winnpoog.exe
- K:\beac
- %User Temp%\winalok.exe
- %User Temp%\winulhug.exe
- L:\c43a
- %User Temp%\winfihk.exe
- M:\c8be
- %User Temp%\winsirwg.exe
- N:\cce5
- %User Temp%\winrhdhy.exe
- O:\d0ec
- %User Temp%\winimfe.exe
- %User Temp%\wincdnu.exe
- P:\d503
- %User Temp%\winshnw.exe
- Q:\d929
- %User Temp%\wingapl.exe
- R:\dd31
- %User Temp%\winixsa.exe
- %User Temp%\winklbku.exe
- S:\e138
- T:\e53f
- %User Temp%\winurlhh.exe
- U:\e956
- %User Temp%\winekhe.exe
- V:\edab
- %User Temp%\winordiid.exe
- %User Temp%\winjhhnds.exe
- W:\f1b3
- %User Temp%\winigmxlq.exe
- X:\f5ba
- %User Temp%\winungvf.exe
- %User Temp%\winwlkldj.exe
- Y:\f9e0
- %User Temp%\winvwljw.exe
- Z:\fdf7
- %User Temp%\winotevys.exe
- %User Temp%\winhafv.exe
- %User Temp%\winnheei.exe
- %User Temp%\winspkxx.exe
- %User Temp%\winwhft.exe
- %User Temp%\winjbhgd.exe
- %User Temp%\winjwrvw.exe
- %User Temp%\wincnoy.exe
- MICROSOFT TERMINAL SERVICES\11383
- %User Temp%\winqailda.exe
- MICROSOFT WINDOWS NETWORK\117b9
- %User Temp%\winckft.exe
- %User Temp%\winhkio.exe
- %User Temp%\winpgwi.exe
- %User Temp%\winkunq.exe
- WORKGROUP\1296c
- %User Temp%\winjoyl.exe
- %User Temp%\winaembos.exe
- %User Temp%\winlrkcxj.exe
(註:%User Temp%フォルダはWindowsの種類とインストール時の設定などにより異なります。標準設定では、Windows 2000、XP および Server 2003 の場合、"C:\Documents and Settings\<ユーザー名>\Local Settings\Temp"、Windows Vista および 7 の場合、"C:\Users\<ユーザ名>\AppData\Local\Temp" です。. %System%フォルダはWindowsの種類とインストール時の設定などにより異なります。標準設定では "C:\Windows\System32" です。. %System Root%フォルダは、標準設定では "C:" です。また、オペレーティングシステムが存在する場所です。)
その他
ウイルスは、以下の不正なWebサイトにアクセスします。
- http://{BLOCKED}wth.com/images/logos.gif?7bd7=221921
- http://www.{BLOCKED}fqwieluoi.info/?71f3=175026
- http://{BLOCKED}ustnet777.info/?93e3=227154
- http://{BLOCKED}pidersm4.{BLOCKED}p.funpic.de/img/mainf.gif?9347=339327
- http://www.{BLOCKED}fe-eg.com/mainh.gif?97bb=77686
- http://{BLOCKED}ny.com/logos.gif?98d5=391250
- http://{BLOCKED}sromance.com/images/mainf.gif?9a5b=158060
- http://www.{BLOCKED}oslaw.yoyo.pl/logos.gif?9ba3=39843
- http://www.{BLOCKED}g-construct.ro/logo.gif?9df5=283059
- http://www.{BLOCKED}yservices.be/images/logos.gif?a0b4=41140
- http://{BLOCKED}wth.com/images/logos.gif?a400=125952
- http://{BLOCKED}pidersm4.{BLOCKED}p.funpic.de/img/mainf.gif?a4cb=126561
- http://www.{BLOCKED}fe-eg.com/mainh.gif?a865=129327
- http://{BLOCKED}ny.com/logos.gif?a8d2=259308
- http://{BLOCKED}sromance.com/images/mainf.gif?a9dc=173936
- http://www.{BLOCKED}oslaw.yoyo.pl/logos.gif?aa78=130920
- http://www.{BLOCKED}g-construct.ro/logo.gif?ab14=262776
- http://www.{BLOCKED}yservices.be/images/logos.gif?ad76=222030
- http://{BLOCKED}wth.com/images/logos.gif?af99=449530
- http://{BLOCKED}pidersm4.{BLOCKED}p.funpic.de/img/mainf.gif?b025=360744
- http://www.{BLOCKED}fe-eg.com/mainh.gif?b40d=230465
- http://{BLOCKED}ny.com/logos.gif?b4aa=462500
- http://{BLOCKED}sromance.com/images/mainf.gif?b69e=140250
- http://www.{BLOCKED}oslaw.yoyo.pl/logos.gif?b70b=421731
- http://www.{BLOCKED}g-construct.ro/logo.gif?b798=188000
- http://www.{BLOCKED}yservices.be/images/logos.gif?ba18=47640
- http://{BLOCKED}wth.com/images/logos.gif?bbdd=48093
- http://{BLOCKED}pidersm4.{BLOCKED}p.funpic.de/img/mainf.gif?bc5a=433962
- http://www.{BLOCKED}fe-eg.com/mainh.gif?c062=98500
- http://{BLOCKED}ny.com/logos.gif?c0fe=345842
- http://{BLOCKED}sromance.com/images/mainf.gif?c1e8=496400
- http://www.{BLOCKED}oslaw.yoyo.pl/logos.gif?c44a=351750
- http://www.{BLOCKED}g-construct.ro/logo.gif?c4f5=352947
- http://www.{BLOCKED}yservices.be/images/logos.gif?c7b5=204500
- http://{BLOCKED}wth.com/images/logos.gif?ca06=517180
- http://{BLOCKED}pidersm4.{BLOCKED}p.funpic.de/img/mainf.gif?ca93=51859
- http://www.{BLOCKED}fe-eg.com/mainh.gif?cfb3=425368
- http://{BLOCKED}ny.com/logos.gif?d050=106656
- http://{BLOCKED}sromance.com/images/mainf.gif?d11b=535310
- http://www.{BLOCKED}oslaw.yoyo.pl/logos.gif?d224=322776
- http://www.{BLOCKED}g-construct.ro/logo.gif?d2ff=162045
- http://www.{BLOCKED}yservices.be/images/logos.gif?d551=163827
- http://{BLOCKED}wth.com/images/logos.gif?d726=275390
- http://{BLOCKED}pidersm4.{BLOCKED}p.funpic.de/img/mainf.gif?d7c2=276170
- http://www.{BLOCKED}fe-eg.com/mainh.gif?dbf8=394184
- http://{BLOCKED}ny.com/logos.gif?dca4=508356
- http://{BLOCKED}sromance.com/images/mainf.gif?dd8e=397026
- http://www.{BLOCKED}oslaw.yoyo.pl/logos.gif?de2b=341250
- http://www.{BLOCKED}g-construct.ro/logo.gif?dee6=285310
- http://www.{BLOCKED}yservices.be/images/logos.gif?e290=406000
- http://{BLOCKED}wth.com/images/logos.gif?e752=532962
- http://{BLOCKED}pidersm4.{BLOCKED}p.funpic.de/img/mainf.gif?e83d=356718
- http://www.{BLOCKED}fe-eg.com/mainh.gif?ebf6=483248
- http://{BLOCKED}ny.com/logos.gif?ec82=363276
- http://{BLOCKED}sromance.com/images/mainf.gif?ed2e=425026
- http://www.{BLOCKED}oslaw.yoyo.pl/logos.gif?ee28=121936
- http://www.{BLOCKED}g-construct.ro/logo.gif?eec5=183375
- http://www.{BLOCKED}yservices.be/images/logos.gif?f136=308750
- http://{BLOCKED}wth.com/images/logos.gif?f2cc=248624
- http://{BLOCKED}pidersm4.{BLOCKED}p.funpic.de/img/mainf.gif?f349=186843
- http://www.{BLOCKED}fe-eg.com/mainh.gif?f79e=507120
- http://{BLOCKED}ny.com/logos.gif?f80c=444500
- http://{BLOCKED}sromance.com/images/mainf.gif?f8c7=127374
- http://www.{BLOCKED}oslaw.yoyo.pl/logos.gif?fa00=128000
- http://www.{BLOCKED}g-construct.ro/logo.gif?faab=192513
- http://www.{BLOCKED}yservices.be/images/logos.gif?fd4b=518744
- http://{BLOCKED}wth.com/images/logos.gif?ff10=326480
- http://{BLOCKED}pidersm4.{BLOCKED}p.funpic.de/img/mainf.gif?ffcc=392904
- http://www.{BLOCKED}fe-eg.com/mainh.gif?1046f=266684
- http://{BLOCKED}ny.com/logos.gif?104ec=200388
- http://{BLOCKED}sromance.com/images/mainf.gif?105d7=670310
- http://www.{BLOCKED}oslaw.yoyo.pl/logos.gif?10635=268500
- http://www.{BLOCKED}g-construct.ro/logo.gif?106d1=605529
- http://www.{BLOCKED}yservices.be/images/logos.gif?10913=339295
- http://{BLOCKED}wth.com/images/logos.gif?10b55=273748
- http://{BLOCKED}pidersm4.{BLOCKED}p.funpic.de/img/mainf.gif?10bf1=342965
- http://www.{BLOCKED}fe-eg.com/mainh.gif?11047=209109
- http://{BLOCKED}ny.com/logos.gif?110b4=558496
- http://{BLOCKED}sromance.com/images/mainf.gif?111be=350390
- http://www.{BLOCKED}oslaw.yoyo.pl/logos.gif?1123b=491421
- http://www.{BLOCKED}g-construct.ro/logo.gif?112c7=492401
- http://www.{BLOCKED}yservices.be/images/logos.gif?11509=354605
- http://{BLOCKED}wth.com/images/logos.gif?116cf=642375
- http://{BLOCKED}pidersm4.{BLOCKED}p.funpic.de/img/mainf.gif?1173c=571872
- http://www.{BLOCKED}fe-eg.com/mainh.gif?11b62=362730
- http://{BLOCKED}ny.com/logos.gif?11c2e=654750
- http://{BLOCKED}sromance.com/images/mainf.gif?11d18=291936
- http://www.{BLOCKED}oslaw.yoyo.pl/logos.gif?11dd3=731710
- http://www.{BLOCKED}g-construct.ro/logo.gif?11edd=587496
- http://www.{BLOCKED}yservices.be/images/logos.gif?1211f=740150
- http://{BLOCKED}wth.com/images/logos.gif?123af=373355
- http://{BLOCKED}pidersm4.{BLOCKED}p.funpic.de/img/mainf.gif?1244c=598624
- http://www.{BLOCKED}fe-eg.com/mainh.gif?128a1=151874
- http://{BLOCKED}ny.com/logos.gif?12a47=687231
- http://{BLOCKED}sromance.com/images/mainf.gif?12b22=536046
- http://www.{BLOCKED}oslaw.yoyo.pl/logos.gif?12c3b=614872
このウイルス情報は、自動解析システムにより作成されました。
対応方法
手順 1
Windows XP、Windows Vista および Windows 7 のユーザは、コンピュータからマルウェアもしくはアドウェア等を完全に削除するために、ウイルス検索の実行前には必ず「システムの復元」を無効にしてください。
手順 2
不明なレジストリ値を削除します。
警告:レジストリはWindowsの構成情報が格納されているデータベースであり、レジストリの編集内容に問題があると、システムが正常に動作しなくなる場合があります。
レジストリの編集はお客様の責任で行っていただくようお願いいたします。弊社ではレジストリの編集による如何なる問題に対しても補償いたしかねます。
レジストリの編集前にこちらをご参照ください。
- In HKEY_CURRENT_USER\Software\Administrator914
- -993627007
手順 3
このレジストリ値を削除します。
警告:レジストリはWindowsの構成情報が格納されているデータベースであり、レジストリの編集内容に問題があると、システムが正常に動作しなくなる場合があります。
レジストリの編集はお客様の責任で行っていただくようお願いいたします。弊社ではレジストリの編集による如何なる問題に対しても補償いたしかねます。
レジストリの編集前にこちらをご参照ください。
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List
- {malware path and file name} = "{malware path and file name}:*:enabled:ipsec"
- In HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
- GlobalUserOffline = "0"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system
- EnableLUA = "0"
- In HKEY_CURRENT_USER\Software\Administrator914\-993627007
- 1768776769 = "4"
- In HKEY_CURRENT_USER\Software\Administrator914\-993627007
- -757413758 = "0"
- In HKEY_CURRENT_USER\Software\Administrator914\-993627007
- 1011363011 = "0"
- In HKEY_CURRENT_USER\Software\Administrator914\-993627007
- -1514827516 = "23"
- In HKEY_CURRENT_USER\Software\Administrator914\-993627007
- 253949253 = "143"
- In HKEY_CURRENT_USER\Software\Administrator914\-993627007
- 2022726022 = "{random characters}"
- In HKEY_CURRENT_USER\Software\Administrator914\-993627007
- -503464505 = "{random characters}"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_0 = "22487345"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_0 = "1bdc"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_0 = "136641"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_0 = "0"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_1 = "b5e2111"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_1 = "696d7a8f"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_1 = "686e2"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_1 = "696d6441"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_2 = "d8186ec1"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_2 = "d2daddc3"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_2 = "d3d9aec3"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_2 = "d2dac882"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_3 = "323bd9a"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_3 = "3c483e72"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_3 = "3d4b4a82"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_3 = "3c482cc3"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_4 = "746b94"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_4 = "a5b584f7"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_4 = "a4b6f745"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_4 = "a5b5914"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_5 = "8111b15"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_5 = "f22eb8b"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_5 = "e21934"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_5 = "f22f545"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_6 = "b2a41f5f"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_6 = "7894d3e"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_6 = "79933fc7"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_6 = "7895986"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_7 = "4db919e"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_7 = "e1fda5c1"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_7 = "efedb86"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_7 = "e1fdbdc7"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_8 = "d3af51"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_8 = "4b6b3444"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_8 = "4a684449"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_8 = "4b6b228"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_9 = "ba7b6b1c"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_9 = "b4d89ced"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_9 = "b5dbe8"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_9 = "b4d88649"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_10 = "25854fd3"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_10 = "1e45f9"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_10 = "1f468ccb"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_10 = "1e45ea8a"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_11 = "6dd19386"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_11 = "87b354bc"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_11 = "86b288a"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_11 = "87b34ecb"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_12 = "1a92ed7a"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_12 = "f12a1c8"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_12 = "f23d54d"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_12 = "f12b3c"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_13 = "fcfb8117"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_13 = "5a8e88e9"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_13 = "5b8d71c"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_13 = "5a8e174d"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_14 = "49759a4d"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_14 = "c3fb6ef2"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_14 = "c2f81dcf"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_14 = "c3fb7b8e"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_15 = "8477f396"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_15 = "2d68ffa2"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_15 = "2c6bb98e"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_15 = "2d68dfcf"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_16 = "1f5d7b67"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_16 = "96d65151"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_16 = "97d52251"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_16 = "96d6441"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_17 = "e21b1484"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_17 = "43baf9"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_17 = "14ce1"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_17 = "43a851"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_18 = "66323ac6"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_18 = "69b11a9a"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_18 = "68b26ad3"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_18 = "69b1c92"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_19 = "b9121a85"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_19 = "d31e66d7"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_19 = "d21d1692"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_19 = "d31e7d3"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_20 = "7347ddd"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_20 = "3c8bc8c1"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_20 = "3d88b355"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_20 = "3c8bd514"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_21 = "6b9511c"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_21 = "a5f92d94"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_21 = "a4fa5f14"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_21 = "a5f93955"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_22 = "adb1a6ac"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_22 = "f66882e"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_22 = "e65fbd7"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_22 = "f669d96"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_23 = "6649b8a"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_23 = "78d41429"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_23 = "79d76796"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_23 = "78d41d7"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_24 = "83b16ed2"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_24 = "e24178e5"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_24 = "e34259"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_24 = "e2416618"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_25 = "1ac5e7"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_25 = "4baed97a"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_25 = "4aadac18"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_25 = "4baeca59"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_26 = "2d833c48"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_26 = "b51c34b2"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_26 = "b41f48db"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_26 = "b51c2e9a"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_27 = "45dd6b85"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_27 = "1e898817"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_27 = "1f8af49a"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_27 = "1e8992db"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_28 = "744fdc5"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_28 = "87f6e52"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_28 = "86f5915d"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_28 = "87f6f71c"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_29 = "b4552e8"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_29 = "f164477d"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_29 = "f673d1c"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_29 = "f1645b5d"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_30 = "ec58ec3"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_30 = "5ad1a7f6"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_30 = "5bd2d9df"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_30 = "5ad1bf9e"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_31 = "65d1586"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_31 = "c43f3b26"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_31 = "c53c459e"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_31 = "c43f23df"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_32 = "d2ca179"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_32 = "2dac8698"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_32 = "2cafee61"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_32 = "2dac882"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_33 = "53dff1"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_33 = "9719f93c"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_33 = "961a8a2"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_33 = "9719ec61"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_34 = "71a533d1"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_34 = "8746a6"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_34 = "18436e3"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_34 = "875a2"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_35 = "3c9f1b3"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_35 = "69f4aed7"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_35 = "68f7d2a2"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_35 = "69f4b4e3"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_36 = "3de187a"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_36 = "d362c79"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_36 = "d2617f65"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_36 = "d3621924"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_37 = "f794a33"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_37 = "3ccf6e27"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_37 = "3dcc1b24"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_37 = "3ccf7d65"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_38 = "83b7ded1"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_38 = "a63cf4e7"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_38 = "a73f87e7"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_38 = "a63ce1a6"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_39 = "cee6f5a"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_39 = "faa53c1"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_39 = "ea923a6"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_39 = "faa45e7"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_40 = "15faca66"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_40 = "7917bf4"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_40 = "7814cc69"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_40 = "7917aa28"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_41 = "82c3753"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_41 = "e2851cf9"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_41 = "e3866828"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_41 = "e285e69"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_42 = "c211c76"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_42 = "4bf26678"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_42 = "4af114eb"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_42 = "4bf272aa"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_43 = "3479c755"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_43 = "b55fc5d3"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_43 = "b45cbaa"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_43 = "b55fd6eb"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_44 = "b63795ef"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_44 = "1ecd282"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_44 = "1fce5d6d"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_44 = "1ecd3b2c"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_45 = "713d3f"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_45 = "883a8f5"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_45 = "8939f92c"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_45 = "883a9f6d"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_46 = "548471fa"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_46 = "f1a81542"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_46 = "fab65ef"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_46 = "f1a83ae"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_47 = "76c32e51"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_47 = "5b157683"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_47 = "5a161ae"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_47 = "5b1567ef"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_48 = "bcb5a46f"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_48 = "c482da8"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_48 = "c581aa71"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_48 = "c482cc3"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_49 = "9f5412c"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_49 = "2df2d45"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_49 = "2cf3563"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_49 = "2df371"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_50 = "31a8b9eb"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_50 = "975d8af9"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_50 = "965ef2f3"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_50 = "975d94b2"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_51 = "4a1a3d86"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_51 = "cae781"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_51 = "1c99eb2"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_51 = "caf8f3"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_52 = "5b892f69"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_52 = "6a38475c"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_52 = "6b3b3b75"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_52 = "6a385d34"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_53 = "5ffb124"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_53 = "d3a5d9fd"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_53 = "d2a6a734"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_53 = "d3a5c175"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_54 = "dbc9c9cd"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_54 = "3d133866"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_54 = "3c143f7"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_54 = "3d1325b6"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_55 = "af921a2"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_55 = "a68934f"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_55 = "a783efb6"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_55 = "a6889f7"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_56 = "de578775"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_56 = "fedf796"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_56 = "eee8879"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_56 = "fedee38"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_57 = "268db1"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_57 = "795b45bc"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_57 = "78583438"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_57 = "795b5279"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_58 = "317cfece"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_58 = "e2c8a11a"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_58 = "e3cbdfb"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_58 = "e2c8b6ba"
手順 4
以下のファイルを検索し削除します。
- %User Temp%\winjbxh.exe
- %User Temp%\winepejmx.exe
- %System%\drivers\oifil.sys
- %User Temp%\winpcrm.exe
- %System Root%\9de5
- D:\a21c
- %User Temp%\wingmxe.exe
- E:\a623
- %User Temp%\winedbv.exe
- F:\aa2a
- %User Temp%\winddgof.exe
- %User Temp%\winjgxc.exe
- G:\ae7f
- %User Temp%\winfkom.exe
- H:\b296
- %User Temp%\winewec.exe
- I:\b6ad
- %User Temp%\winmieot.exe
- %User Temp%\winwcypi.exe
- J:\baa5
- %User Temp%\winnpoog.exe
- K:\beac
- %User Temp%\winalok.exe
- %User Temp%\winulhug.exe
- L:\c43a
- %User Temp%\winfihk.exe
- M:\c8be
- %User Temp%\winsirwg.exe
- N:\cce5
- %User Temp%\winrhdhy.exe
- O:\d0ec
- %User Temp%\winimfe.exe
- %User Temp%\wincdnu.exe
- P:\d503
- %User Temp%\winshnw.exe
- Q:\d929
- %User Temp%\wingapl.exe
- R:\dd31
- %User Temp%\winixsa.exe
- %User Temp%\winklbku.exe
- S:\e138
- T:\e53f
- %User Temp%\winurlhh.exe
- U:\e956
- %User Temp%\winekhe.exe
- V:\edab
- %User Temp%\winordiid.exe
- %User Temp%\winjhhnds.exe
- W:\f1b3
- %User Temp%\winigmxlq.exe
- X:\f5ba
- %User Temp%\winungvf.exe
- %User Temp%\winwlkldj.exe
- Y:\f9e0
- %User Temp%\winvwljw.exe
- Z:\fdf7
- %User Temp%\winotevys.exe
- %User Temp%\winhafv.exe
- %User Temp%\winnheei.exe
- %User Temp%\winspkxx.exe
- %User Temp%\winwhft.exe
- %User Temp%\winjbhgd.exe
- %User Temp%\winjwrvw.exe
- %User Temp%\wincnoy.exe
- MICROSOFT TERMINAL SERVICES\11383
- %User Temp%\winqailda.exe
- MICROSOFT WINDOWS NETWORK\117b9
- %User Temp%\winckft.exe
- %User Temp%\winhkio.exe
- %User Temp%\winpgwi.exe
- %User Temp%\winkunq.exe
- WORKGROUP\1296c
- %User Temp%\winjoyl.exe
- %User Temp%\winaembos.exe
- %User Temp%\winlrkcxj.exe
手順 5
最新のバージョン(エンジン、パターンファイル)を導入したウイルス対策製品を用い、「PE_SALITY.M」と検出したファイルの駆除を実行してください。 検出されたファイルが、弊社ウイルス対策製品により既に駆除、隔離またはファイル削除の処理が実行された場合、ウイルスの処理は完了しており、他の削除手順は特にありません。
手順 6
以下の削除されたレジストリキーまたはレジストリ値をバックアップを用いて修復します。
※註:マイクロソフト製品に関連したレジストリキーおよびレジストリ値のみが修復されます。このマルウェアもしくはアドウェア等が同社製品以外のプログラムも削除した場合には、該当プログラムを再度インストールする必要があります。
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- AppMgmt
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- Base
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- Boot Bus Extender
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- Boot file system
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- CryptSvc
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- DcomLaunch
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- dmadmin
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- dmboot.sys
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- dmio.sys
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- dmload.sys
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- dmserver
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- EventLog
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- File system
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- Filter
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- HelpSvc
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- Netlogon
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- PCI Configuration
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- PlugPlay
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- PNP Filter
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- Primary disk
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- RpcSs
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- SCSI Class
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- sermouse.sys
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- sr.sys
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- SRService
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- System Bus Extender
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- vga.sys
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- vgasave.sys
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- WinMgmt
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- {36FC9E60-C465-11CF-8056-444553540000}
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- {4D36E965-E325-11CE-BFC1-08002BE10318}
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- {4D36E967-E325-11CE-BFC1-08002BE10318}
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- {4D36E969-E325-11CE-BFC1-08002BE10318}
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- {4D36E96A-E325-11CE-BFC1-08002BE10318}
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- {4D36E96B-E325-11CE-BFC1-08002BE10318}
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- {4D36E96F-E325-11CE-BFC1-08002BE10318}
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- {4D36E977-E325-11CE-BFC1-08002BE10318}
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- {4D36E97B-E325-11CE-BFC1-08002BE10318}
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- {4D36E97D-E325-11CE-BFC1-08002BE10318}
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- {4D36E980-E325-11CE-BFC1-08002BE10318}
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- {71A27CDD-812A-11D0-BEC7-08002BE2092F}
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- {745A17A0-74D3-11D0-B6FE-00A0C90F57DA}
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot
- Minimal
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- AFD
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- AppMgmt
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- Base
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- Boot Bus Extender
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- Boot file system
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- Browser
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- CryptSvc
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- DcomLaunch
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- Dhcp
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- dmadmin
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- dmboot.sys
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- dmio.sys
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- dmload.sys
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- dmserver
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- DnsCache
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- EventLog
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- File system
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- Filter
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- HelpSvc
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- ip6fw.sys
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- ipnat.sys
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- LanmanServer
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- LanmanWorkstation
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- LmHosts
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- Messenger
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- NDIS
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- NDIS Wrapper
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- Ndisuio
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- NetBIOS
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- NetBIOSGroup
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- NetBT
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- NetDDEGroup
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- Netlogon
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- NetMan
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot
- Network
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- NetworkProvider
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- NtLmSsp
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- PCI Configuration
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- PlugPlay
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- PNP Filter
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- PNP_TDI
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- Primary disk
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- rdpcdd.sys
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- rdpdd.sys
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- rdpwd.sys
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- rdsessmgr
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- RpcSs
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- SCSI Class
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- sermouse.sys
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- SharedAccess
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- sr.sys
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- SRService
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- Streams Drivers
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- System Bus Extender
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- Tcpip
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- TDI
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- tdpipe.sys
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- tdtcp.sys
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- termservice
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- vga.sys
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- vgasave.sys
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- WinMgmt
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- WZCSVC
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- {36FC9E60-C465-11CF-8056-444553540000}
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- {4D36E965-E325-11CE-BFC1-08002BE10318}
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- {4D36E967-E325-11CE-BFC1-08002BE10318}
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- {4D36E969-E325-11CE-BFC1-08002BE10318}
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- {4D36E96A-E325-11CE-BFC1-08002BE10318}
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- {4D36E96B-E325-11CE-BFC1-08002BE10318}
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- {4D36E96F-E325-11CE-BFC1-08002BE10318}
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- {4D36E972-E325-11CE-BFC1-08002BE10318}
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- {4D36E973-E325-11CE-BFC1-08002BE10318}
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- {4D36E974-E325-11CE-BFC1-08002BE10318}
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- {4D36E975-E325-11CE-BFC1-08002BE10318}
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- {4D36E977-E325-11CE-BFC1-08002BE10318}
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- {4D36E97B-E325-11CE-BFC1-08002BE10318}
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- {4D36E97D-E325-11CE-BFC1-08002BE10318}
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- {4D36E980-E325-11CE-BFC1-08002BE10318}
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- {71A27CDD-812A-11D0-BEC7-08002BE2092F}
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- {745A17A0-74D3-11D0-B6FE-00A0C90F57DA}
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot
- Network
ご利用はいかがでしたか? アンケートにご協力ください