BKDR_BFROSE.SMAA
Backdoor:Win32/Bifrose (Microsoft); BackDoor-CEP.svr (McAfee); Trojan Horse (Symantec); Trojan.Win32.Agent.bcn, Backdoor.Win32.Bifrose.aci (Kaspersky); Win32.Sality.ek (v) (Sunbelt); Backdoor.Bifrost.IS (FSecure)
Windows 2000, Windows XP, Windows Server 2003
マルウェアタイプ:
バックドア型
破壊活動の有無:
なし
暗号化:
感染報告の有無 :
はい
概要
マルウェアは、他のマルウェアに作成されるか、悪意あるWebサイトからユーザが誤ってダウンロードすることによりコンピュータに侵入します。
詳細
侵入方法
マルウェアは、他のマルウェアに作成されるか、悪意あるWebサイトからユーザが誤ってダウンロードすることによりコンピュータに侵入します。
他のシステム変更
マルウェアは、以下のレジストリキーを追加します。
HKEY_CURRENT_USER\Software\Administrator914\
-993627007
マルウェアは、以下のレジストリ値を追加します。
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Internet Settings
GlobalUserOffline = "0"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\policies\
system
EnableLUA = "0"
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Services\SharedAccess\Parameters\
FirewallPolicy\StandardProfile\AuthorizedApplications\
List
{malware path and file name} = "{malware path and file name}:*:enabled:ipsec"
HKEY_CURRENT_USER\Software\Administrator914\
-993627007
1768776769 = "e"
HKEY_CURRENT_USER\Software\Administrator914\
-993627007
-757413758 = "0"
HKEY_CURRENT_USER\Software\Administrator914\
-993627007
1011363011 = "0"
HKEY_CURRENT_USER\Software\Administrator914\
-993627007
-1514827516 = "23"
HKEY_CURRENT_USER\Software\Administrator914\
-993627007
253949253 = "1d3"
HKEY_CURRENT_USER\Software\Administrator914\
-993627007
2022726022 = "{random characters}"
HKEY_CURRENT_USER\Software\Administrator914\
-993627007
-503464505 = "{random characters}"
HKEY_CURRENT_USER\Software\Administrator914
A1_0 = "12da4c5e"
HKEY_CURRENT_USER\Software\Administrator914
A2_0 = "6cf"
HKEY_CURRENT_USER\Software\Administrator914
A3_0 = "136641"
HKEY_CURRENT_USER\Software\Administrator914
A4_0 = "0"
HKEY_CURRENT_USER\Software\Administrator914
A1_1 = "b1a3281f"
HKEY_CURRENT_USER\Software\Administrator914
A2_1 = "696d628e"
HKEY_CURRENT_USER\Software\Administrator914
A3_1 = "686e2"
HKEY_CURRENT_USER\Software\Administrator914
A4_1 = "696d6441"
HKEY_CURRENT_USER\Software\Administrator914
A1_2 = "7fac238"
HKEY_CURRENT_USER\Software\Administrator914
A2_2 = "d2dad173"
HKEY_CURRENT_USER\Software\Administrator914
A3_2 = "d3d9aec3"
HKEY_CURRENT_USER\Software\Administrator914
A4_2 = "d2dac882"
HKEY_CURRENT_USER\Software\Administrator914
A1_3 = "1d19f7d"
HKEY_CURRENT_USER\Software\Administrator914
A2_3 = "3c483532"
HKEY_CURRENT_USER\Software\Administrator914
A3_3 = "3d4b4a82"
HKEY_CURRENT_USER\Software\Administrator914
A4_3 = "3c482cc3"
HKEY_CURRENT_USER\Software\Administrator914
A1_4 = "ccc8f3b9"
HKEY_CURRENT_USER\Software\Administrator914
A2_4 = "a5b58ae8"
HKEY_CURRENT_USER\Software\Administrator914
A3_4 = "a4b6f745"
HKEY_CURRENT_USER\Software\Administrator914
A4_4 = "a5b5914"
HKEY_CURRENT_USER\Software\Administrator914
A1_5 = "62d684f8"
HKEY_CURRENT_USER\Software\Administrator914
A2_5 = "f22ee23"
HKEY_CURRENT_USER\Software\Administrator914
A3_5 = "e21934"
HKEY_CURRENT_USER\Software\Administrator914
A4_5 = "f22f545"
HKEY_CURRENT_USER\Software\Administrator914
A1_6 = "bf83fde"
HKEY_CURRENT_USER\Software\Administrator914
A2_6 = "7894ed5"
HKEY_CURRENT_USER\Software\Administrator914
A3_6 = "79933fc7"
HKEY_CURRENT_USER\Software\Administrator914
A4_6 = "7895986"
HKEY_CURRENT_USER\Software\Administrator914
A1_7 = "63f1f613"
HKEY_CURRENT_USER\Software\Administrator914
A2_7 = "e1fdae85"
HKEY_CURRENT_USER\Software\Administrator914
A3_7 = "efedb86"
HKEY_CURRENT_USER\Software\Administrator914
A4_7 = "e1fdbdc7"
HKEY_CURRENT_USER\Software\Administrator914
A1_8 = "5495edb6"
HKEY_CURRENT_USER\Software\Administrator914
A2_8 = "4b6b395"
HKEY_CURRENT_USER\Software\Administrator914
A3_8 = "4a684449"
HKEY_CURRENT_USER\Software\Administrator914
A4_8 = "4b6b228"
HKEY_CURRENT_USER\Software\Administrator914
A1_9 = "dcfd3a7"
HKEY_CURRENT_USER\Software\Administrator914
A2_9 = "b4d8936e"
HKEY_CURRENT_USER\Software\Administrator914
A3_9 = "b5dbe8"
HKEY_CURRENT_USER\Software\Administrator914
A4_9 = "b4d88649"
HKEY_CURRENT_USER\Software\Administrator914
A1_10 = "ab7facc7"
HKEY_CURRENT_USER\Software\Administrator914
A2_10 = "1e45fab"
HKEY_CURRENT_USER\Software\Administrator914
A3_10 = "1f468ccb"
HKEY_CURRENT_USER\Software\Administrator914
A4_10 = "1e45ea8a"
HKEY_CURRENT_USER\Software\Administrator914
A1_11 = "95fe775"
HKEY_CURRENT_USER\Software\Administrator914
A2_11 = "87b35d8b"
HKEY_CURRENT_USER\Software\Administrator914
A3_11 = "86b288a"
HKEY_CURRENT_USER\Software\Administrator914
A4_11 = "87b34ecb"
HKEY_CURRENT_USER\Software\Administrator914
A1_12 = "3523d52"
HKEY_CURRENT_USER\Software\Administrator914
A2_12 = "f1296c6"
HKEY_CURRENT_USER\Software\Administrator914
A3_12 = "f23d54d"
HKEY_CURRENT_USER\Software\Administrator914
A4_12 = "f12b3c"
HKEY_CURRENT_USER\Software\Administrator914
A1_13 = "86ed763"
HKEY_CURRENT_USER\Software\Administrator914
A2_13 = "5a8ecb5"
HKEY_CURRENT_USER\Software\Administrator914
A3_13 = "5b8d71c"
HKEY_CURRENT_USER\Software\Administrator914
A4_13 = "5a8e174d"
HKEY_CURRENT_USER\Software\Administrator914
A1_14 = "be4b2fe"
HKEY_CURRENT_USER\Software\Administrator914
A2_14 = "c3fb6c57"
HKEY_CURRENT_USER\Software\Administrator914
A3_14 = "c2f81dcf"
HKEY_CURRENT_USER\Software\Administrator914
A4_14 = "c3fb7b8e"
HKEY_CURRENT_USER\Software\Administrator914
A1_15 = "7d9ed91"
HKEY_CURRENT_USER\Software\Administrator914
A2_15 = "2d68ca31"
HKEY_CURRENT_USER\Software\Administrator914
A3_15 = "2c6bb98e"
HKEY_CURRENT_USER\Software\Administrator914
A4_15 = "2d68dfcf"
HKEY_CURRENT_USER\Software\Administrator914
A1_16 = "b5e56ac"
HKEY_CURRENT_USER\Software\Administrator914
A2_16 = "96d65c98"
HKEY_CURRENT_USER\Software\Administrator914
A3_16 = "97d52251"
HKEY_CURRENT_USER\Software\Administrator914
A4_16 = "96d6441"
HKEY_CURRENT_USER\Software\Administrator914
A1_17 = "e6b5e"
HKEY_CURRENT_USER\Software\Administrator914
A2_17 = "43b179"
HKEY_CURRENT_USER\Software\Administrator914
A3_17 = "14ce1"
HKEY_CURRENT_USER\Software\Administrator914
A4_17 = "43a851"
HKEY_CURRENT_USER\Software\Administrator914
A1_18 = "4a7362e2"
HKEY_CURRENT_USER\Software\Administrator914
A2_18 = "69b11952"
HKEY_CURRENT_USER\Software\Administrator914
A3_18 = "68b26ad3"
HKEY_CURRENT_USER\Software\Administrator914
A4_18 = "69b1c92"
HKEY_CURRENT_USER\Software\Administrator914
A1_19 = "65b368"
HKEY_CURRENT_USER\Software\Administrator914
A2_19 = "d31e6dfb"
HKEY_CURRENT_USER\Software\Administrator914
A3_19 = "d21d1692"
HKEY_CURRENT_USER\Software\Administrator914
A4_19 = "d31e7d3"
HKEY_CURRENT_USER\Software\Administrator914
A1_20 = "2925d95c"
HKEY_CURRENT_USER\Software\Administrator914
A2_20 = "3c8bcd53"
HKEY_CURRENT_USER\Software\Administrator914
A3_20 = "3d88b355"
HKEY_CURRENT_USER\Software\Administrator914
A4_20 = "3c8bd514"
HKEY_CURRENT_USER\Software\Administrator914
A1_21 = "31d1c51"
HKEY_CURRENT_USER\Software\Administrator914
A2_21 = "a5f9243f"
HKEY_CURRENT_USER\Software\Administrator914
A3_21 = "a4fa5f14"
HKEY_CURRENT_USER\Software\Administrator914
A4_21 = "a5f93955"
HKEY_CURRENT_USER\Software\Administrator914
A1_22 = "feab9f28"
HKEY_CURRENT_USER\Software\Administrator914
A2_22 = "f6684ee"
HKEY_CURRENT_USER\Software\Administrator914
A3_22 = "e65fbd7"
HKEY_CURRENT_USER\Software\Administrator914
A4_22 = "f669d96"
HKEY_CURRENT_USER\Software\Administrator914
A1_23 = "593728ab"
HKEY_CURRENT_USER\Software\Administrator914
A2_23 = "78d41a2f"
HKEY_CURRENT_USER\Software\Administrator914
A3_23 = "79d76796"
HKEY_CURRENT_USER\Software\Administrator914
A4_23 = "78d41d7"
HKEY_CURRENT_USER\Software\Administrator914
A1_24 = "8d51e64a"
HKEY_CURRENT_USER\Software\Administrator914
A2_24 = "e2417713"
HKEY_CURRENT_USER\Software\Administrator914
A3_24 = "e34259"
HKEY_CURRENT_USER\Software\Administrator914
A4_24 = "e2416618"
HKEY_CURRENT_USER\Software\Administrator914
A1_25 = "646e4be5"
HKEY_CURRENT_USER\Software\Administrator914
A2_25 = "4baed2f"
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Services\SharedAccess\Parameters\
FirewallPolicy\StandardProfile\AuthorizedApplications\
List
%Windows%\Explorer.EXE = "%Windows%\Explorer.EXE:*:Enabled:ipsec"
HKEY_CURRENT_USER\Software\Administrator914\
-993627007
1768776769 = "f8"
HKEY_CURRENT_USER\Software\Administrator914\
-993627007
253949253 = "fd"
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Services\SharedAccess\Parameters\
FirewallPolicy\StandardProfile\AuthorizedApplications\
List
%User Temp%\winlfpee.exe = "%User Temp%\winlfpee.exe:*:Enabled:ipsec"
HKEY_CURRENT_USER\Software\Administrator914
A4_0 = "82"
HKEY_CURRENT_USER\Software\Administrator914
A4_1 = "696d64c3"
HKEY_CURRENT_USER\Software\Administrator914
A1_2 = "c84dc"
HKEY_CURRENT_USER\Software\Administrator914
A2_2 = "d2dace4d"
HKEY_CURRENT_USER\Software\Administrator914
A4_2 = "d2dac8"
HKEY_CURRENT_USER\Software\Administrator914
A1_3 = "e48669d"
HKEY_CURRENT_USER\Software\Administrator914
A2_3 = "3c482ac"
HKEY_CURRENT_USER\Software\Administrator914
A4_3 = "3c482c41"
HKEY_CURRENT_USER\Software\Administrator914
A1_4 = "b76fdd5a"
HKEY_CURRENT_USER\Software\Administrator914
A2_4 = "a5b597cb"
HKEY_CURRENT_USER\Software\Administrator914
A4_4 = "a5b59186"
HKEY_CURRENT_USER\Software\Administrator914
A1_5 = "d7ecb91b"
HKEY_CURRENT_USER\Software\Administrator914
A2_5 = "f22f38a"
HKEY_CURRENT_USER\Software\Administrator914
A4_5 = "f22f5c7"
HKEY_CURRENT_USER\Software\Administrator914
A1_6 = "6a4a15d8"
HKEY_CURRENT_USER\Software\Administrator914
A2_6 = "7895f49"
HKEY_CURRENT_USER\Software\Administrator914
A4_6 = "789594"
HKEY_CURRENT_USER\Software\Administrator914
A1_7 = "3933f199"
HKEY_CURRENT_USER\Software\Administrator914
A2_7 = "e1fdbb8"
HKEY_CURRENT_USER\Software\Administrator914
A4_7 = "e1fdbd45"
HKEY_CURRENT_USER\Software\Administrator914
A1_8 = "59b16e56"
HKEY_CURRENT_USER\Software\Administrator914
A2_8 = "4b6b24c7"
HKEY_CURRENT_USER\Software\Administrator914
A4_8 = "4b6b228a"
HKEY_CURRENT_USER\Software\Administrator914
A1_9 = "6c16ca17"
HKEY_CURRENT_USER\Software\Administrator914
A2_9 = "b4d8886"
HKEY_CURRENT_USER\Software\Administrator914
A4_9 = "b4d886cb"
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Services\SharedAccess\Parameters\
FirewallPolicy\StandardProfile\AuthorizedApplications\
List
%User Temp%\winlhvuq.exe = "%User Temp%\winlhvuq.exe:*:Enabled:ipsec"
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Services\SharedAccess\Parameters\
FirewallPolicy\StandardProfile\AuthorizedApplications\
List
%User Temp%\winqupxrs.exe = "%User Temp%\winqupxrs.exe:*:Enabled:ipsec"
マルウェアは、以下のレジストリキーを削除します。
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
AppMgmt
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
Base
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
Boot Bus Extender
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
Boot file system
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
CryptSvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
DcomLaunch
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
dmadmin
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
dmboot.sys
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
dmio.sys
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
dmload.sys
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
dmserver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
EventLog
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
File system
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
Filter
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
HelpSvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
Netlogon
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
PCI Configuration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
PNP Filter
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
Primary disk
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
RpcSs
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
SCSI Class
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
sermouse.sys
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
sr.sys
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
SRService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
System Bus Extender
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
vga.sys
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
vgasave.sys
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
WinMgmt
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
{36FC9E60-C465-11CF-8056-444553540000}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
{4D36E965-E325-11CE-BFC1-08002BE10318}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
{4D36E967-E325-11CE-BFC1-08002BE10318}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
{4D36E969-E325-11CE-BFC1-08002BE10318}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
{4D36E96A-E325-11CE-BFC1-08002BE10318}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
{4D36E96B-E325-11CE-BFC1-08002BE10318}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
{4D36E96F-E325-11CE-BFC1-08002BE10318}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
{4D36E977-E325-11CE-BFC1-08002BE10318}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
{4D36E97B-E325-11CE-BFC1-08002BE10318}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
{4D36E97D-E325-11CE-BFC1-08002BE10318}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
{4D36E980-E325-11CE-BFC1-08002BE10318}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
{71A27CDD-812A-11D0-BEC7-08002BE2092F}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal\
{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Minimal
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
AFD
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
AppMgmt
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
Base
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
Boot Bus Extender
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
Boot file system
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
Browser
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
CryptSvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
DcomLaunch
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
Dhcp
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
dmadmin
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
dmboot.sys
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
dmio.sys
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
dmload.sys
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
dmserver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
DnsCache
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
EventLog
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
File system
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
Filter
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
HelpSvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
ip6fw.sys
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
ipnat.sys
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
LanmanServer
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
LanmanWorkstation
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
LmHosts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
Messenger
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
NDIS
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
NDIS Wrapper
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
Ndisuio
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
NetBIOS
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
NetBIOSGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
NetBT
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
NetDDEGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
Netlogon
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
NetMan
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
Network
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
NetworkProvider
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
NtLmSsp
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
PCI Configuration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
PlugPlay
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
PNP Filter
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
PNP_TDI
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
Primary disk
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
rdpcdd.sys
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
rdpdd.sys
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
rdpwd.sys
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
rdsessmgr
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
RpcSs
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
SCSI Class
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
sermouse.sys
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
SharedAccess
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
sr.sys
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
SRService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
Streams Drivers
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
System Bus Extender
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
Tcpip
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
TDI
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
tdpipe.sys
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
tdtcp.sys
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
termservice
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
vga.sys
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
vgasave.sys
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
WinMgmt
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
WZCSVC
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
{36FC9E60-C465-11CF-8056-444553540000}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
{4D36E965-E325-11CE-BFC1-08002BE10318}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
{4D36E967-E325-11CE-BFC1-08002BE10318}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
{4D36E969-E325-11CE-BFC1-08002BE10318}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
{4D36E96A-E325-11CE-BFC1-08002BE10318}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
{4D36E96B-E325-11CE-BFC1-08002BE10318}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
{4D36E96F-E325-11CE-BFC1-08002BE10318}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
{4D36E972-E325-11CE-BFC1-08002BE10318}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
{4D36E973-E325-11CE-BFC1-08002BE10318}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
{4D36E974-E325-11CE-BFC1-08002BE10318}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
{4D36E975-E325-11CE-BFC1-08002BE10318}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
{4D36E977-E325-11CE-BFC1-08002BE10318}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
{4D36E97B-E325-11CE-BFC1-08002BE10318}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
{4D36E97D-E325-11CE-BFC1-08002BE10318}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
{4D36E980-E325-11CE-BFC1-08002BE10318}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
{71A27CDD-812A-11D0-BEC7-08002BE2092F}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network\
{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Control\SafeBoot\Network
作成活動
マルウェアは、以下のファイルを作成します。
- %System%\drivers\jlone.sys
- %System Root%\a78a
- D:\ab91
- E:\af99
- F:\b41d
- %User Temp%\winaamnn.exe
- G:\b824
- %User Temp%\winbjldqp.exe
- H:\bc2b
- %User Temp%\winxxlri.exe
- %User Temp%\windcvto.exe
- I:\c033
- J:\c43a
- K:\c841
- L:\cc48
- M:\d0bd
- %User Temp%\winlaajj.exe
- N:\d4d4
- O:\d8eb
- P:\dd02
- %User Temp%\winfdos.exe
- Q:\e128
- R:\e53f
- %User Temp%\winlfpee.exe
- S:\e956
- T:\ed6d
- U:\f1a3
- %User Temp%\wininbfn.exe
- V:\f666
- %User Temp%\winlhvuq.exe
- W:\fb19
- X:\ff5f
- Y:\10385
- %User Temp%\winverv.exe
- Z:\107cb
- %User Temp%\wineaoxix.exe
- %User Temp%\winqupxrs.exe
- MICROSOFT TERMINAL SERVICES\118b3
- MICROSOFT WINDOWS NETWORK\11d85
- %User Temp%\winwwqdn.exe
- %User Temp%\winjrtc.exe
- WORKGROUP\12eac
- %User Temp%\winchkjp.exe
- \BRIAN-03A68ED\1360f
- %User Temp%\winired.exe
(註:%System%はWindowsの種類とインストール時の設定などにより異なります。標準設定では、Windows 98 および MEの場合、"C:\Windows\System"、Windows NT および 2000 の場合、"C:\WinNT\System32"、Windows XP および Server 2003 の場合、"C:\Windows\System32" です。. %System Root%は、標準設定では "C:" です。また、オペレーティングシステムが存在する場所です。. %User Temp%はWindowsの種類とインストール時の設定などにより異なります。標準設定では、Windows 98 および MEの場合、"C:\Windows\Temp"、Windows NT の場合、"C:\Profiles\<ユーザー名>\TEMP"、Windows 2000、XP、Server 2003 の場合、"C:\Documents and Settings\<ユーザー名>\Local Settings\TEMP" です。)
その他
マルウェアは、以下の不正なWebサイトにアクセスします。
- http://{BLOCKED}sgharanakathak.com/logo.gif?8f5f=183515
- http://www.{BLOCKED}fqwieluoi.info/?8f01=73218
- http://{BLOCKED}ustnet777.info/?a066=369558
- http://{BLOCKED}web.in/images/logo.gif?9f6c=367308
- http://{BLOCKED}gateway.org/images/logo.gif?b12f=272154
- http://{BLOCKED}tak.com/images/logo.gif?b536=92780
- http://{BLOCKED}go.cl/images/logo.gif?b6cc=327572
- http://{BLOCKED}ocen.pl/fmain.gif?b9ca=428058
- http://baranlar.{BLOCKED}m.tr/images/logo.gif?bc89=482650
- http://bibliotekagim2.{BLOCKED}u.pl/images/fmain.gif?c023=147561
- http://www.{BLOCKED}parthotel.com/logo.gif?c4c7=453375
- http://{BLOCKED}ak.com/images/logo.gif?c62e=405872
- http://{BLOCKED}reinfo.com/images/logo2.gif?cf27=159093
- http://{BLOCKED}express.com/images/fmain.gif?cfc3=319122
- http://koksumran.{BLOCKED}o.th/lo{BLOCKED}o.gif?da81=111874
- http://mejorporinternet.{BLOCKED}m.ar/logo.gif?dd11=452744
- http://{BLOCKED}r.nl/logo.gif?e176=577180
- http://www.{BLOCKED}n-hrb.com/logo.gif?e5bc=58812
- http://{BLOCKED}aircraft.com/logo.gif?f08a=307890
- http://expo.{BLOCKED}es.com/logo.gif?f2ad=497000
- http://{BLOCKED}marphotography.in/images/logo.gif?10412=532624
- http://koksumran.{BLOCKED}o.th/lo{BLOCKED}o.gif?10877=67703
- http://mejorporinternet.{BLOCKED}m.ar/logo.gif?10b74=684680
- http://{BLOCKED}r.nl/logo.gif?11170=630000
- http://www.{BLOCKED}n-hrb.com/logo.gif?11603=284684
- http://{BLOCKED}aircraft.com/logo.gif?1214e=296248
- http://expo.{BLOCKED}es.com/logo.gif?122c5=223311
- http://{BLOCKED}marphotography.in/images/logo.gif?13284=313872
- http://koksumran.{BLOCKED}o.th/lo{BLOCKED}o.gif?1362e=158812
このウイルス情報は、自動解析システムにより作成されました。
対応方法
手順 1
Windows XP および Windows Server 2003 のユーザは、コンピュータからマルウェアもしくはアドウェア等を完全に削除するために、ウイルス検索の実行前には必ず「システムの復元」を無効にしてください。
手順 2
このレジストリキーを削除します。
警告:レジストリはWindowsの構成情報が格納されているデータベースであり、レジストリの編集内容に問題があると、システムが正常に動作しなくなる場合があります。
レジストリの編集はお客様の責任で行っていただくようお願いいたします。弊社ではレジストリの編集による如何なる問題に対しても補償いたしかねます。
レジストリの編集前にこちらをご参照ください。
- In HKEY_CURRENT_USER\Software\Administrator914
- -993627007
手順 3
このレジストリ値を削除します。
警告:レジストリはWindowsの構成情報が格納されているデータベースであり、レジストリの編集内容に問題があると、システムが正常に動作しなくなる場合があります。
レジストリの編集はお客様の責任で行っていただくようお願いいたします。弊社ではレジストリの編集による如何なる問題に対しても補償いたしかねます。
レジストリの編集前にこちらをご参照ください。
- In HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
- GlobalUserOffline = "0"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system
- EnableLUA = "0"
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List
- {malware path and file name} = "{malware path and file name}:*:enabled:ipsec"
- In HKEY_CURRENT_USER\Software\Administrator914\-993627007
- 1768776769 = "e"
- In HKEY_CURRENT_USER\Software\Administrator914\-993627007
- -757413758 = "0"
- In HKEY_CURRENT_USER\Software\Administrator914\-993627007
- 1011363011 = "0"
- In HKEY_CURRENT_USER\Software\Administrator914\-993627007
- -1514827516 = "23"
- In HKEY_CURRENT_USER\Software\Administrator914\-993627007
- 253949253 = "1d3"
- In HKEY_CURRENT_USER\Software\Administrator914\-993627007
- 2022726022 = "{random characters}"
- In HKEY_CURRENT_USER\Software\Administrator914\-993627007
- -503464505 = "{random characters}"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_0 = "12da4c5e"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_0 = "6cf"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_0 = "136641"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_0 = "0"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_1 = "b1a3281f"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_1 = "696d628e"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_1 = "686e2"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_1 = "696d6441"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_2 = "7fac238"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_2 = "d2dad173"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_2 = "d3d9aec3"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_2 = "d2dac882"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_3 = "1d19f7d"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_3 = "3c483532"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_3 = "3d4b4a82"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_3 = "3c482cc3"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_4 = "ccc8f3b9"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_4 = "a5b58ae8"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_4 = "a4b6f745"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_4 = "a5b5914"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_5 = "62d684f8"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_5 = "f22ee23"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_5 = "e21934"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_5 = "f22f545"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_6 = "bf83fde"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_6 = "7894ed5"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_6 = "79933fc7"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_6 = "7895986"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_7 = "63f1f613"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_7 = "e1fdae85"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_7 = "efedb86"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_7 = "e1fdbdc7"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_8 = "5495edb6"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_8 = "4b6b395"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_8 = "4a684449"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_8 = "4b6b228"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_9 = "dcfd3a7"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_9 = "b4d8936e"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_9 = "b5dbe8"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_9 = "b4d88649"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_10 = "ab7facc7"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_10 = "1e45fab"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_10 = "1f468ccb"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_10 = "1e45ea8a"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_11 = "95fe775"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_11 = "87b35d8b"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_11 = "86b288a"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_11 = "87b34ecb"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_12 = "3523d52"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_12 = "f1296c6"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_12 = "f23d54d"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_12 = "f12b3c"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_13 = "86ed763"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_13 = "5a8ecb5"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_13 = "5b8d71c"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_13 = "5a8e174d"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_14 = "be4b2fe"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_14 = "c3fb6c57"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_14 = "c2f81dcf"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_14 = "c3fb7b8e"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_15 = "7d9ed91"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_15 = "2d68ca31"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_15 = "2c6bb98e"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_15 = "2d68dfcf"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_16 = "b5e56ac"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_16 = "96d65c98"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_16 = "97d52251"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_16 = "96d6441"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_17 = "e6b5e"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_17 = "43b179"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_17 = "14ce1"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_17 = "43a851"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_18 = "4a7362e2"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_18 = "69b11952"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_18 = "68b26ad3"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_18 = "69b1c92"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_19 = "65b368"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_19 = "d31e6dfb"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_19 = "d21d1692"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_19 = "d31e7d3"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_20 = "2925d95c"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_20 = "3c8bcd53"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_20 = "3d88b355"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_20 = "3c8bd514"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_21 = "31d1c51"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_21 = "a5f9243f"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_21 = "a4fa5f14"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_21 = "a5f93955"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_22 = "feab9f28"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_22 = "f6684ee"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_22 = "e65fbd7"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_22 = "f669d96"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_23 = "593728ab"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_23 = "78d41a2f"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_23 = "79d76796"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_23 = "78d41d7"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_24 = "8d51e64a"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_24 = "e2417713"
- In HKEY_CURRENT_USER\Software\Administrator914
- A3_24 = "e34259"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_24 = "e2416618"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_25 = "646e4be5"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_25 = "4baed2f"
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List
- %Windows%\Explorer.EXE = "%Windows%\Explorer.EXE:*:Enabled:ipsec"
- In HKEY_CURRENT_USER\Software\Administrator914\-993627007
- 1768776769 = "f8"
- In HKEY_CURRENT_USER\Software\Administrator914\-993627007
- 253949253 = "fd"
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List
- %User Temp%\winlfpee.exe = "%User Temp%\winlfpee.exe:*:Enabled:ipsec"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_0 = "82"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_1 = "696d64c3"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_2 = "c84dc"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_2 = "d2dace4d"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_2 = "d2dac8"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_3 = "e48669d"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_3 = "3c482ac"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_3 = "3c482c41"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_4 = "b76fdd5a"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_4 = "a5b597cb"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_4 = "a5b59186"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_5 = "d7ecb91b"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_5 = "f22f38a"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_5 = "f22f5c7"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_6 = "6a4a15d8"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_6 = "7895f49"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_6 = "789594"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_7 = "3933f199"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_7 = "e1fdbb8"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_7 = "e1fdbd45"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_8 = "59b16e56"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_8 = "4b6b24c7"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_8 = "4b6b228a"
- In HKEY_CURRENT_USER\Software\Administrator914
- A1_9 = "6c16ca17"
- In HKEY_CURRENT_USER\Software\Administrator914
- A2_9 = "b4d8886"
- In HKEY_CURRENT_USER\Software\Administrator914
- A4_9 = "b4d886cb"
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List
- %User Temp%\winlhvuq.exe = "%User Temp%\winlhvuq.exe:*:Enabled:ipsec"
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List
- %User Temp%\winqupxrs.exe = "%User Temp%\winqupxrs.exe:*:Enabled:ipsec"
手順 4
以下のファイルを検索し削除します。
- %System%\drivers\jlone.sys
- %System Root%\a78a
- D:\ab91
- E:\af99
- F:\b41d
- %User Temp%\winaamnn.exe
- G:\b824
- %User Temp%\winbjldqp.exe
- H:\bc2b
- %User Temp%\winxxlri.exe
- %User Temp%\windcvto.exe
- I:\c033
- J:\c43a
- K:\c841
- L:\cc48
- M:\d0bd
- %User Temp%\winlaajj.exe
- N:\d4d4
- O:\d8eb
- P:\dd02
- %User Temp%\winfdos.exe
- Q:\e128
- R:\e53f
- %User Temp%\winlfpee.exe
- S:\e956
- T:\ed6d
- U:\f1a3
- %User Temp%\wininbfn.exe
- V:\f666
- %User Temp%\winlhvuq.exe
- W:\fb19
- X:\ff5f
- Y:\10385
- %User Temp%\winverv.exe
- Z:\107cb
- %User Temp%\wineaoxix.exe
- %User Temp%\winqupxrs.exe
- MICROSOFT TERMINAL SERVICES\118b3
- MICROSOFT WINDOWS NETWORK\11d85
- %User Temp%\winwwqdn.exe
- %User Temp%\winjrtc.exe
- WORKGROUP\12eac
- %User Temp%\winchkjp.exe
- \BRIAN-03A68ED\1360f
- %User Temp%\winired.exe
手順 5
最新のバージョン(エンジン、パターンファイル)を導入したウイルス対策製品を用い、ウイルス検索を実行してください。「BKDR_BFROSE.SMAA」と検出したファイルはすべて削除してください。 検出されたファイルが、弊社ウイルス対策製品により既に駆除、隔離またはファイル削除の処理が実行された場合、ウイルスの処理は完了しており、他の削除手順は特にありません。
手順 6
以下の削除されたレジストリキーまたはレジストリ値をバックアップを用いて修復します。
※註:マイクロソフト製品に関連したレジストリキーおよびレジストリ値のみが修復されます。このマルウェアもしくはアドウェア等が同社製品以外のプログラムも削除した場合には、該当プログラムを再度インストールする必要があります。
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- AppMgmt
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- Base
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- Boot Bus Extender
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- Boot file system
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- CryptSvc
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- DcomLaunch
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- dmadmin
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- dmboot.sys
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- dmio.sys
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- dmload.sys
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- dmserver
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- EventLog
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- File system
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- Filter
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- HelpSvc
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- Netlogon
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- PCI Configuration
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- PNP Filter
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- Primary disk
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- RpcSs
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- SCSI Class
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- sermouse.sys
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- sr.sys
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- SRService
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- System Bus Extender
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- vga.sys
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- vgasave.sys
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- WinMgmt
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- {36FC9E60-C465-11CF-8056-444553540000}
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- {4D36E965-E325-11CE-BFC1-08002BE10318}
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- {4D36E967-E325-11CE-BFC1-08002BE10318}
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- {4D36E969-E325-11CE-BFC1-08002BE10318}
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- {4D36E96A-E325-11CE-BFC1-08002BE10318}
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- {4D36E96B-E325-11CE-BFC1-08002BE10318}
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- {4D36E96F-E325-11CE-BFC1-08002BE10318}
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- {4D36E977-E325-11CE-BFC1-08002BE10318}
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- {4D36E97B-E325-11CE-BFC1-08002BE10318}
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- {4D36E97D-E325-11CE-BFC1-08002BE10318}
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- {4D36E980-E325-11CE-BFC1-08002BE10318}
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- {71A27CDD-812A-11D0-BEC7-08002BE2092F}
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal
- {745A17A0-74D3-11D0-B6FE-00A0C90F57DA}
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot
- Minimal
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- AFD
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- AppMgmt
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- Base
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- Boot Bus Extender
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- Boot file system
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- Browser
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- CryptSvc
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- DcomLaunch
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- Dhcp
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- dmadmin
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- dmboot.sys
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- dmio.sys
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- dmload.sys
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- dmserver
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- DnsCache
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- EventLog
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- File system
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- Filter
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- HelpSvc
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- ip6fw.sys
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- ipnat.sys
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- LanmanServer
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- LanmanWorkstation
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- LmHosts
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- Messenger
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- NDIS
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- NDIS Wrapper
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- Ndisuio
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- NetBIOS
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- NetBIOSGroup
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- NetBT
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- NetDDEGroup
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- Netlogon
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- NetMan
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot
- Network
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- NetworkProvider
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- NtLmSsp
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- PCI Configuration
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- PlugPlay
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- PNP Filter
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- PNP_TDI
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- Primary disk
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- rdpcdd.sys
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- rdpdd.sys
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- rdpwd.sys
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- rdsessmgr
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- RpcSs
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- SCSI Class
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- sermouse.sys
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- SharedAccess
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- sr.sys
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- SRService
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- Streams Drivers
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- System Bus Extender
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- Tcpip
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- TDI
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- tdpipe.sys
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- tdtcp.sys
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- termservice
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- vga.sys
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- vgasave.sys
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- WinMgmt
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- WZCSVC
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- {36FC9E60-C465-11CF-8056-444553540000}
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- {4D36E965-E325-11CE-BFC1-08002BE10318}
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- {4D36E967-E325-11CE-BFC1-08002BE10318}
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- {4D36E969-E325-11CE-BFC1-08002BE10318}
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- {4D36E96A-E325-11CE-BFC1-08002BE10318}
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- {4D36E96B-E325-11CE-BFC1-08002BE10318}
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- {4D36E96F-E325-11CE-BFC1-08002BE10318}
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- {4D36E972-E325-11CE-BFC1-08002BE10318}
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- {4D36E973-E325-11CE-BFC1-08002BE10318}
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- {4D36E974-E325-11CE-BFC1-08002BE10318}
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- {4D36E975-E325-11CE-BFC1-08002BE10318}
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- {4D36E977-E325-11CE-BFC1-08002BE10318}
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- {4D36E97B-E325-11CE-BFC1-08002BE10318}
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- {4D36E97D-E325-11CE-BFC1-08002BE10318}
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- {4D36E980-E325-11CE-BFC1-08002BE10318}
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- {71A27CDD-812A-11D0-BEC7-08002BE2092F}
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network
- {745A17A0-74D3-11D0-B6FE-00A0C90F57DA}
- In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot
- Network
ご利用はいかがでしたか? アンケートにご協力ください