TROJ_VB.BJR
Trojan:Win32/VB.NP (Microsoft); W32/PJTbinder!hv (McAfee); W32.Pajetbin (Symantec); Trojan.Win32.VB.chg, Trojan.Win32.VB.chg (Kaspersky); Trojan.Win32.VB.chg (v) (Sunbelt); Win32.HLLP.VB.K (FSecure)
Windows 2000, Windows XP, Windows Server 2003
マルウェアタイプ:
トロイの木馬型
破壊活動の有無:
なし
暗号化:
感染報告の有無 :
はい
概要
マルウェアは、他のマルウェアに作成されるか、悪意あるWebサイトからユーザが誤ってダウンロードすることによりコンピュータに侵入します。
詳細
侵入方法
マルウェアは、他のマルウェアに作成されるか、悪意あるWebサイトからユーザが誤ってダウンロードすることによりコンピュータに侵入します。
インストール
マルウェアは、以下のフォルダを作成します。
- %System Root%\10a0699fa37928d39c
- %Temporary Internet Files%\Content.IE5\2C10A89
(註:%System Root%フォルダは、標準設定では "C:" です。また、オペレーティングシステムが存在する場所です。. %Temporary Internet Files%フォルダは、Windows 2000、XP および Server 2003 の場合、通常、"C:\Documents and Settings\<ユーザ名>\Local Settings\Temporary Internet Files"、Windows Vista および 7 の場合、"C:\Users\<ユーザ名>\AppData\Local\Microsoft\Windows\Temporary Internet Files" です。)
自動実行方法
マルウェアは、自身のコピーがWindows起動時に自動実行されるよう以下のレジストリ値を追加します。
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Run
FileProtector = "%System Root%\10a0699fa37928d39c\spfirewall.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Run
RegSCRLib = "regsvr32.exe /s scrrun.dll"
他のシステム変更
マルウェアは、以下のファイルを削除します。
- %Desktop%\vcredist_x86.exe
- %Desktop%\WinPcap_4_1_2.exe
- %Program Files%\Common Files\Microsoft Shared\MSInfo\msinfo32.exe
- %Program Files%\Common Files\Microsoft Shared\Speech\sapisvr.exe
- %Program Files%\Internet Explorer\Connection Wizard\icwconn1.exe
- %Program Files%\Internet Explorer\Connection Wizard\icwconn2.exe
- %Program Files%\Internet Explorer\Connection Wizard\icwrmind.exe
- %Program Files%\Internet Explorer\Connection Wizard\icwtutor.exe
- %Program Files%\Internet Explorer\Connection Wizard\inetwiz.exe
- %Program Files%\Internet Explorer\Connection Wizard\isignup.exe
- %Program Files%\Internet Explorer\iedw.exe
- %Program Files%\Internet Explorer\IEXPLORE.EXE
- %Program Files%\Messenger\msmsgs.exe
- %Program Files%\Movie Maker\moviemk.exe
- %Program Files%\MSN\MSNCoreFiles\Install\MSN9Components\Digcore.exe
- %Program Files%\MSN\MSNCoreFiles\Install\MSN9Components\Msncli.exe
- %Program Files%\MSN\MSNCoreFiles\Install\msnsusii.exe
- %Program Files%\MSN Gaming Zone\Windows\bckgzm.exe
- %Program Files%\MSN Gaming Zone\Windows\chkrzm.exe
- %Program Files%\MSN Gaming Zone\Windows\hrtzzm.exe
- %Program Files%\MSN Gaming Zone\Windows\Rvsezm.exe
- %Program Files%\MSN Gaming Zone\Windows\shvlzm.exe
- %Program Files%\MSN Gaming Zone\Windows\zClientm.exe
- %Program Files%\NetMeeting\cb32.exe
- %Program Files%\NetMeeting\conf.exe
- %Program Files%\NetMeeting\wb32.exe
- %Program Files%\Outlook Express\msimn.exe
- %Program Files%\Outlook Express\oemig50.exe
- %Program Files%\Outlook Express\setup50.exe
- %Program Files%\Outlook Express\wab.exe
- %Program Files%\Outlook Express\wabmig.exe
- %Program Files%\Windows Media Player\migrate.exe
- %Program Files%\Windows Media Player\mplayer2.exe
- %Program Files%\Windows Media Player\setup_wm.exe
- %Program Files%\Windows Media Player\wmplayer.exe
- %Program Files%\Windows NT\Accessories\wordpad.exe
- %Program Files%\Windows NT\Pinball\PINBALL.EXE
- %Program Files%\Windows NT\dialer.exe
- %Program Files%\Windows NT\hypertrm.exe
- %Program Files%\WinPcap\rpcapd.exe
- %Program Files%\WinPcap\Uninstall.exe
- %Windows%\Help\Tours\mmTour\tour.exe
- %Windows%\inf\unregmp2.exe
- %Windows%\Installer\{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}\places.exe
(註:%Desktop%フォルダは、Windows 2000、XP および Server 2003 の場合、通常 "C:\Documents and Settings\<ユーザ名>\デスクトップ"、Windows Vista および 7 の場合、"C:\Users\<ユーザ名>\デスクトップ" です。. %Program Files%フォルダは、Windows 2000、Server 2003、XP (32ビット)、通常 Vista (32ビット) および 7 (32ビット) の場合、通常 "C:\Program Files"、Windows XP (64ビット)、Vista (64ビット) および 7 (64ビット) の場合、通常 "C:\Program Files (x86)" です。. %Windows%フォルダはWindowsの種類とインストール時の設定などにより異なります。標準設定では、"C:\Windows" です。)
マルウェアは、以下のレジストリキーを追加します。
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
TypeLib\{420B2830-E718-11CF-893D-00A0C9054228}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
TypeLib\{420B2830-E718-11CF-893D-00A0C9054228}\1.0\
0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{EE09B103-97E0-11CF-978F-00A02463E06F}\Implemented Categories
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{EE09B103-97E0-11CF-978F-00A02463E06F}\Implemented Categories\
{7DD95801-9882-11CF-9FA9-00AA006C42C4}
HKEY_CLASSES_ROOT\HTML.HostEncode
HKEY_CLASSES_ROOT\ASP.HostEncode
HKEY_CLASSES_ROOT\JSFile.HostEncode
HKEY_CLASSES_ROOT\VBSFile.HostEncode
マルウェアは、以下のレジストリ値を追加します。
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{EE09B103-97E0-11CF-978F-00A02463E06F}
TypeLib = "{420B2830-E718-11CF-893D-00A0C9054228}"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{EE09B103-97E0-11CF-978F-00A02463E06F}
Version = "1.0"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{EE09B103-97E0-11CF-978F-00A02463E06F}
ProgID = "Scripting.Dictionary"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Scripting.Dictionary
CLSID = "{EE09B103-97E0-11CF-978F-00A02463E06F}"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{0D43FE01-F093-11CF-8940-00A0C9054228}
TypeLib = "{420B2830-E718-11CF-893D-00A0C9054228}"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{0D43FE01-F093-11CF-8940-00A0C9054228}
Version = "1.0"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{0D43FE01-F093-11CF-8940-00A0C9054228}
ProgID = "Scripting.FileSystemObject"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Scripting.FileSystemObject
CLSID = "{0D43FE01-F093-11CF-8940-00A0C9054228}"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{32DA2B15-CFED-11D1-B747-00C04FC2B085}
TypeLib = "{420B2830-E718-11CF-893D-00A0C9054228}"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{32DA2B15-CFED-11D1-B747-00C04FC2B085}
Version = "1.0"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{32DA2B15-CFED-11D1-B747-00C04FC2B085}
ProgID = "Scripting.Encoder"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Scripting.Encoder
CLSID = "{32DA2B15-CFED-11D1-B747-00C04FC2B085}"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{0CF774D0-F077-11D1-B1BC-00C04F86C324}
InprocServer32 = "%System%\scrrun.dll"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{0CF774D0-F077-11D1-B1BC-00C04F86C324}
ProgID = "HTML.HostEncode"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
HTML.HostEncode
CLSID = "{0CF774D0-F077-11D1-B1BC-00C04F86C324}"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{0CF774D1-F077-11D1-B1BC-00C04F86C324}
InprocServer32 = "%System%\scrrun.dll"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{0CF774D1-F077-11D1-B1BC-00C04F86C324}
ProgID = "ASP.HostEncode"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
ASP.HostEncode
CLSID = "{0CF774D1-F077-11D1-B1BC-00C04F86C324}"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{85131630-480C-11D2-B1F9-00C04F86C324}
InprocServer32 = "%System%\scrrun.dll"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{85131630-480C-11D2-B1F9-00C04F86C324}
ProgID = "JSFile.HostEncode"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
JSFile.HostEncode
CLSID = "{85131630-480C-11D2-B1F9-00C04F86C324}"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{85131631-480C-11D2-B1F9-00C04F86C324}
InprocServer32 = "%System%\scrrun.dll"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{85131631-480C-11D2-B1F9-00C04F86C324}
ProgID = "VBSFile.HostEncode"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
VBSFile.HostEncode
CLSID = "{85131631-480C-11D2-B1F9-00C04F86C324}"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
htmlfile
ScriptHostEncode = "{0CF774D0-F077-11D1-B1BC-00C04F86C324}"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
aspfile
ScriptHostEncode = "{0CF774D1-F077-11D1-B1BC-00C04F86C324}"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
JSFile
ScriptHostEncode = "{85131630-480C-11D2-B1F9-00C04F86C324}"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
VBSFile
ScriptHostEncode = "{85131631-480C-11D2-B1F9-00C04F86C324}"
マルウェアは、以下のレジストリ値を変更します。
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{42C642C1-97E1-11CF-978F-00A02463E06F}\TypeLib
Version = "1.0"
(註:変更前の上記レジストリ値は、「1.0」となります。)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{0AB5A3D0-E5B6-11D0-ABF5-00A0C90FFFC0}\TypeLib
Version = "1.0"
(註:変更前の上記レジストリ値は、「1.0」となります。)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{C7C3F5A1-88A3-11D0-ABCB-00A0C90FFFC0}\TypeLib
Version = "1.0"
(註:変更前の上記レジストリ値は、「1.0」となります。)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{C7C3F5A0-88A3-11D0-ABCB-00A0C90FFFC0}\TypeLib
Version = "1.0"
(註:変更前の上記レジストリ値は、「1.0」となります。)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{C7C3F5A2-88A3-11D0-ABCB-00A0C90FFFC0}\TypeLib
Version = "1.0"
(註:変更前の上記レジストリ値は、「1.0」となります。)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{C7C3F5A3-88A3-11D0-ABCB-00A0C90FFFC0}\TypeLib
Version = "1.0"
(註:変更前の上記レジストリ値は、「1.0」となります。)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{C7C3F5A5-88A3-11D0-ABCB-00A0C90FFFC0}\TypeLib
Version = "1.0"
(註:変更前の上記レジストリ値は、「1.0」となります。)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{C7C3F5A4-88A3-11D0-ABCB-00A0C90FFFC0}\TypeLib
Version = "1.0"
(註:変更前の上記レジストリ値は、「1.0」となります。)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{53BAD8C1-E718-11CF-893D-00A0C9054228}\TypeLib
Version = "1.0"
(註:変更前の上記レジストリ値は、「1.0」となります。)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{2A0B9D10-4B87-11D3-A97A-00104B365C9F}\TypeLib
Version = "1.0"
(註:変更前の上記レジストリ値は、「1.0」となります。)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{AADC65F6-CFF1-11D1-B747-00C04FC2B085}\TypeLib
Version = "1.0"
(註:変更前の上記レジストリ値は、「1.0」となります。)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{EE09B103-97E0-11CF-978F-00A02463E06F}\InprocServer32
ThreadingModel = "Apartment"
(註:変更前の上記レジストリ値は、「Apartment」となります。)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{0D43FE01-F093-11CF-8940-00A0C9054228}\InprocServer32
ThreadingModel = "Both"
(註:変更前の上記レジストリ値は、「Both」となります。)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{32DA2B15-CFED-11D1-B747-00C04FC2B085}\InprocServer32
ThreadingModel = "Apartment"
(註:変更前の上記レジストリ値は、「Apartment」となります。)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{0CF774D0-F077-11D1-B1BC-00C04F86C324}\InprocServer32
ThreadingModel = "Apartment"
(註:変更前の上記レジストリ値は、「Apartment」となります。)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{0CF774D1-F077-11D1-B1BC-00C04F86C324}\InprocServer32
ThreadingModel = "Apartment"
(註:変更前の上記レジストリ値は、「Apartment」となります。)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{85131630-480C-11D2-B1F9-00C04F86C324}\InprocServer32
ThreadingModel = "Apartment"
(註:変更前の上記レジストリ値は、「Apartment」となります。)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{85131631-480C-11D2-B1F9-00C04F86C324}\InprocServer32
ThreadingModel = "Apartment"
(註:変更前の上記レジストリ値は、「Apartment」となります。)
マルウェアは、以下のレジストリキーを削除します。
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{EE09B103-97E0-11CF-978F-00A02463E06F}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{EE09B103-97E0-11CF-978F-00A02463E06F}\TypeLib
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{EE09B103-97E0-11CF-978F-00A02463E06F}\Version
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{EE09B103-97E0-11CF-978F-00A02463E06F}\ProgID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{EE09B103-97E0-11CF-978F-00A02463E06F}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Scripting.Dictionary\CLSID
HKEY_CLASSES_ROOT\Scripting.Dictionary
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{0D43FE01-F093-11CF-8940-00A0C9054228}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{0D43FE01-F093-11CF-8940-00A0C9054228}\TypeLib
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{0D43FE01-F093-11CF-8940-00A0C9054228}\Version
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{0D43FE01-F093-11CF-8940-00A0C9054228}\ProgID
{7DD95801-9882-11CF-9FA9-00AA006C42C4}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{0D43FE01-F093-11CF-8940-00A0C9054228}\Implemented Categories
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{0D43FE01-F093-11CF-8940-00A0C9054228}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Scripting.FileSystemObject\CLSID
HKEY_CLASSES_ROOT\Scripting.FileSystemObject
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{32DA2B15-CFED-11D1-B747-00C04FC2B085}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{32DA2B15-CFED-11D1-B747-00C04FC2B085}\TypeLib
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{32DA2B15-CFED-11D1-B747-00C04FC2B085}\Version
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{32DA2B15-CFED-11D1-B747-00C04FC2B085}\ProgID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{32DA2B15-CFED-11D1-B747-00C04FC2B085}\Implemented Categories
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{32DA2B15-CFED-11D1-B747-00C04FC2B085}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Scripting.Encoder\CLSID
HKEY_CLASSES_ROOT\Scripting.Encoder
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{0CF774D0-F077-11D1-B1BC-00C04F86C324}\ProgID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{0CF774D0-F077-11D1-B1BC-00C04F86C324}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{0CF774D0-F077-11D1-B1BC-00C04F86C324}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
HTML.HostEncode\CLSID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{0CF774D1-F077-11D1-B1BC-00C04F86C324}\ProgID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{0CF774D1-F077-11D1-B1BC-00C04F86C324}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{0CF774D1-F077-11D1-B1BC-00C04F86C324}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
ASP.HostEncode\CLSID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{85131630-480C-11D2-B1F9-00C04F86C324}\ProgID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{85131630-480C-11D2-B1F9-00C04F86C324}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{85131630-480C-11D2-B1F9-00C04F86C324}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
JSFile.HostEncode\CLSID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{85131631-480C-11D2-B1F9-00C04F86C324}\ProgID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{85131631-480C-11D2-B1F9-00C04F86C324}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{85131631-480C-11D2-B1F9-00C04F86C324}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
VBSFile.HostEncode\CLSID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
htmlfile\ScriptHostEncode
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
aspfile\ScriptHostEncode
HKEY_CLASSES_ROOT\aspfile
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
JSFile\ScriptHostEncode
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
VBSFile\ScriptHostEncode
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
TypeLib\{420B2830-E718-11CF-893D-00A0C9054228}\1.0\
0\win32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
TypeLib\{420B2830-E718-11CF-893D-00A0C9054228}\1.0\
FLAGS
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
TypeLib\{420B2830-E718-11CF-893D-00A0C9054228}\1.0\
HELPDIR
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
TypeLib\{420B2830-E718-11CF-893D-00A0C9054228}\1.0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{42C642C1-97E1-11CF-978F-00A02463E06F}\ProxyStubClsid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{42C642C1-97E1-11CF-978F-00A02463E06F}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{42C642C1-97E1-11CF-978F-00A02463E06F}\TypeLib
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{42C642C1-97E1-11CF-978F-00A02463E06F}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{0AB5A3D0-E5B6-11D0-ABF5-00A0C90FFFC0}\ProxyStubClsid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{0AB5A3D0-E5B6-11D0-ABF5-00A0C90FFFC0}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{0AB5A3D0-E5B6-11D0-ABF5-00A0C90FFFC0}\TypeLib
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{0AB5A3D0-E5B6-11D0-ABF5-00A0C90FFFC0}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{C7C3F5A1-88A3-11D0-ABCB-00A0C90FFFC0}\ProxyStubClsid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{C7C3F5A1-88A3-11D0-ABCB-00A0C90FFFC0}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{C7C3F5A1-88A3-11D0-ABCB-00A0C90FFFC0}\TypeLib
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{C7C3F5A1-88A3-11D0-ABCB-00A0C90FFFC0}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{C7C3F5A0-88A3-11D0-ABCB-00A0C90FFFC0}\ProxyStubClsid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{C7C3F5A0-88A3-11D0-ABCB-00A0C90FFFC0}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{C7C3F5A0-88A3-11D0-ABCB-00A0C90FFFC0}\TypeLib
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{C7C3F5A0-88A3-11D0-ABCB-00A0C90FFFC0}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{C7C3F5A2-88A3-11D0-ABCB-00A0C90FFFC0}\ProxyStubClsid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{C7C3F5A2-88A3-11D0-ABCB-00A0C90FFFC0}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{C7C3F5A2-88A3-11D0-ABCB-00A0C90FFFC0}\TypeLib
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{C7C3F5A2-88A3-11D0-ABCB-00A0C90FFFC0}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{C7C3F5A3-88A3-11D0-ABCB-00A0C90FFFC0}\ProxyStubClsid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{C7C3F5A3-88A3-11D0-ABCB-00A0C90FFFC0}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{C7C3F5A3-88A3-11D0-ABCB-00A0C90FFFC0}\TypeLib
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{C7C3F5A3-88A3-11D0-ABCB-00A0C90FFFC0}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{C7C3F5A5-88A3-11D0-ABCB-00A0C90FFFC0}\ProxyStubClsid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{C7C3F5A5-88A3-11D0-ABCB-00A0C90FFFC0}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{C7C3F5A5-88A3-11D0-ABCB-00A0C90FFFC0}\TypeLib
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{C7C3F5A5-88A3-11D0-ABCB-00A0C90FFFC0}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{C7C3F5A4-88A3-11D0-ABCB-00A0C90FFFC0}\ProxyStubClsid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{C7C3F5A4-88A3-11D0-ABCB-00A0C90FFFC0}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{C7C3F5A4-88A3-11D0-ABCB-00A0C90FFFC0}\TypeLib
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{C7C3F5A4-88A3-11D0-ABCB-00A0C90FFFC0}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{53BAD8C1-E718-11CF-893D-00A0C9054228}\ProxyStubClsid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{53BAD8C1-E718-11CF-893D-00A0C9054228}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{53BAD8C1-E718-11CF-893D-00A0C9054228}\TypeLib
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{53BAD8C1-E718-11CF-893D-00A0C9054228}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{2A0B9D10-4B87-11D3-A97A-00104B365C9F}\ProxyStubClsid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{2A0B9D10-4B87-11D3-A97A-00104B365C9F}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{2A0B9D10-4B87-11D3-A97A-00104B365C9F}\TypeLib
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{2A0B9D10-4B87-11D3-A97A-00104B365C9F}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{AADC65F6-CFF1-11D1-B747-00C04FC2B085}\ProxyStubClsid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{AADC65F6-CFF1-11D1-B747-00C04FC2B085}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{AADC65F6-CFF1-11D1-B747-00C04FC2B085}\TypeLib
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{AADC65F6-CFF1-11D1-B747-00C04FC2B085}
作成活動
マルウェアは、以下のファイルを作成します。
- %System Root%\10a0699fa37928d39c\spinst.exe
(註:%System Root%フォルダは、標準設定では "C:" です。また、オペレーティングシステムが存在する場所です。)
このウイルス情報は、自動解析システムにより作成されました。
対応方法
手順 1
Windows XP、Windows Vista および Windows 7 のユーザは、コンピュータからマルウェアもしくはアドウェア等を完全に削除するために、ウイルス検索の実行前には必ず「システムの復元」を無効にしてください。
手順 2
Windowsをセーフモードで再起動します。
手順 3
このレジストリキーを削除します。
警告:レジストリはWindowsの構成情報が格納されているデータベースであり、レジストリの編集内容に問題があると、システムが正常に動作しなくなる場合があります。
レジストリの編集はお客様の責任で行っていただくようお願いいたします。弊社ではレジストリの編集による如何なる問題に対しても補償いたしかねます。
レジストリの編集前にこちらをご参照ください。
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib
- {420B2830-E718-11CF-893D-00A0C9054228}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{420B2830-E718-11CF-893D-00A0C9054228}\1.0
- 0
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EE09B103-97E0-11CF-978F-00A02463E06F}
- Implemented Categories
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EE09B103-97E0-11CF-978F-00A02463E06F}\Implemented Categories
- {7DD95801-9882-11CF-9FA9-00AA006C42C4}
- In HKEY_CLASSES_ROOT
- HTML.HostEncode
- In HKEY_CLASSES_ROOT
- ASP.HostEncode
- In HKEY_CLASSES_ROOT
- JSFile.HostEncode
- In HKEY_CLASSES_ROOT
- VBSFile.HostEncode
手順 4
このレジストリ値を削除します。
警告:レジストリはWindowsの構成情報が格納されているデータベースであり、レジストリの編集内容に問題があると、システムが正常に動作しなくなる場合があります。
レジストリの編集はお客様の責任で行っていただくようお願いいたします。弊社ではレジストリの編集による如何なる問題に対しても補償いたしかねます。
レジストリの編集前にこちらをご参照ください。
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
- FileProtector = "%System Root%\10a0699fa37928d39c\spfirewall.exe"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
- RegSCRLib = "regsvr32.exe /s scrrun.dll"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EE09B103-97E0-11CF-978F-00A02463E06F}
- TypeLib = "{420B2830-E718-11CF-893D-00A0C9054228}"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EE09B103-97E0-11CF-978F-00A02463E06F}
- Version = "1.0"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EE09B103-97E0-11CF-978F-00A02463E06F}
- ProgID = "Scripting.Dictionary"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Scripting.Dictionary
- CLSID = "{EE09B103-97E0-11CF-978F-00A02463E06F}"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0D43FE01-F093-11CF-8940-00A0C9054228}
- TypeLib = "{420B2830-E718-11CF-893D-00A0C9054228}"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0D43FE01-F093-11CF-8940-00A0C9054228}
- Version = "1.0"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0D43FE01-F093-11CF-8940-00A0C9054228}
- ProgID = "Scripting.FileSystemObject"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Scripting.FileSystemObject
- CLSID = "{0D43FE01-F093-11CF-8940-00A0C9054228}"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{32DA2B15-CFED-11D1-B747-00C04FC2B085}
- TypeLib = "{420B2830-E718-11CF-893D-00A0C9054228}"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{32DA2B15-CFED-11D1-B747-00C04FC2B085}
- Version = "1.0"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{32DA2B15-CFED-11D1-B747-00C04FC2B085}
- ProgID = "Scripting.Encoder"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Scripting.Encoder
- CLSID = "{32DA2B15-CFED-11D1-B747-00C04FC2B085}"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0CF774D0-F077-11D1-B1BC-00C04F86C324}
- InprocServer32 = "%System%\scrrun.dll"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0CF774D0-F077-11D1-B1BC-00C04F86C324}
- ProgID = "HTML.HostEncode"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\HTML.HostEncode
- CLSID = "{0CF774D0-F077-11D1-B1BC-00C04F86C324}"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0CF774D1-F077-11D1-B1BC-00C04F86C324}
- InprocServer32 = "%System%\scrrun.dll"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0CF774D1-F077-11D1-B1BC-00C04F86C324}
- ProgID = "ASP.HostEncode"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ASP.HostEncode
- CLSID = "{0CF774D1-F077-11D1-B1BC-00C04F86C324}"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{85131630-480C-11D2-B1F9-00C04F86C324}
- InprocServer32 = "%System%\scrrun.dll"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{85131630-480C-11D2-B1F9-00C04F86C324}
- ProgID = "JSFile.HostEncode"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\JSFile.HostEncode
- CLSID = "{85131630-480C-11D2-B1F9-00C04F86C324}"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{85131631-480C-11D2-B1F9-00C04F86C324}
- InprocServer32 = "%System%\scrrun.dll"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{85131631-480C-11D2-B1F9-00C04F86C324}
- ProgID = "VBSFile.HostEncode"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VBSFile.HostEncode
- CLSID = "{85131631-480C-11D2-B1F9-00C04F86C324}"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\htmlfile
- ScriptHostEncode = "{0CF774D0-F077-11D1-B1BC-00C04F86C324}"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\aspfile
- ScriptHostEncode = "{0CF774D1-F077-11D1-B1BC-00C04F86C324}"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\JSFile
- ScriptHostEncode = "{85131630-480C-11D2-B1F9-00C04F86C324}"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VBSFile
- ScriptHostEncode = "{85131631-480C-11D2-B1F9-00C04F86C324}"
手順 5
変更されたレジストリ値を修正します。
警告:レジストリはWindowsの構成情報が格納されているデータベースであり、レジストリの編集内容に問題があると、システムが正常に動作しなくなる場合があります。
レジストリの編集はお客様の責任で行っていただくようお願いいたします。弊社ではレジストリの編集による如何なる問題に対しても補償いたしかねます。
レジストリの編集前にこちらをご参照ください。
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{42C642C1-97E1-11CF-978F-00A02463E06F}\TypeLib
- From: Version = "1.0"
To: Version = ""1.0""
- From: Version = "1.0"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0AB5A3D0-E5B6-11D0-ABF5-00A0C90FFFC0}\TypeLib
- From: Version = "1.0"
To: Version = ""1.0""
- From: Version = "1.0"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C7C3F5A1-88A3-11D0-ABCB-00A0C90FFFC0}\TypeLib
- From: Version = "1.0"
To: Version = ""1.0""
- From: Version = "1.0"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C7C3F5A0-88A3-11D0-ABCB-00A0C90FFFC0}\TypeLib
- From: Version = "1.0"
To: Version = ""1.0""
- From: Version = "1.0"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C7C3F5A2-88A3-11D0-ABCB-00A0C90FFFC0}\TypeLib
- From: Version = "1.0"
To: Version = ""1.0""
- From: Version = "1.0"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C7C3F5A3-88A3-11D0-ABCB-00A0C90FFFC0}\TypeLib
- From: Version = "1.0"
To: Version = ""1.0""
- From: Version = "1.0"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C7C3F5A5-88A3-11D0-ABCB-00A0C90FFFC0}\TypeLib
- From: Version = "1.0"
To: Version = ""1.0""
- From: Version = "1.0"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C7C3F5A4-88A3-11D0-ABCB-00A0C90FFFC0}\TypeLib
- From: Version = "1.0"
To: Version = ""1.0""
- From: Version = "1.0"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{53BAD8C1-E718-11CF-893D-00A0C9054228}\TypeLib
- From: Version = "1.0"
To: Version = ""1.0""
- From: Version = "1.0"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2A0B9D10-4B87-11D3-A97A-00104B365C9F}\TypeLib
- From: Version = "1.0"
To: Version = ""1.0""
- From: Version = "1.0"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{AADC65F6-CFF1-11D1-B747-00C04FC2B085}\TypeLib
- From: Version = "1.0"
To: Version = ""1.0""
- From: Version = "1.0"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EE09B103-97E0-11CF-978F-00A02463E06F}\InprocServer32
- From: ThreadingModel = "Apartment"
To: ThreadingModel = ""Apartment""
- From: ThreadingModel = "Apartment"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0D43FE01-F093-11CF-8940-00A0C9054228}\InprocServer32
- From: ThreadingModel = "Both"
To: ThreadingModel = ""Both""
- From: ThreadingModel = "Both"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{32DA2B15-CFED-11D1-B747-00C04FC2B085}\InprocServer32
- From: ThreadingModel = "Apartment"
To: ThreadingModel = ""Apartment""
- From: ThreadingModel = "Apartment"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0CF774D0-F077-11D1-B1BC-00C04F86C324}\InprocServer32
- From: ThreadingModel = "Apartment"
To: ThreadingModel = ""Apartment""
- From: ThreadingModel = "Apartment"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0CF774D1-F077-11D1-B1BC-00C04F86C324}\InprocServer32
- From: ThreadingModel = "Apartment"
To: ThreadingModel = ""Apartment""
- From: ThreadingModel = "Apartment"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{85131630-480C-11D2-B1F9-00C04F86C324}\InprocServer32
- From: ThreadingModel = "Apartment"
To: ThreadingModel = ""Apartment""
- From: ThreadingModel = "Apartment"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{85131631-480C-11D2-B1F9-00C04F86C324}\InprocServer32
- From: ThreadingModel = "Apartment"
To: ThreadingModel = ""Apartment""
- From: ThreadingModel = "Apartment"
手順 6
以下のファイルを検索し削除します。
- %System Root%\10a0699fa37928d39c\spinst.exe
手順 7
以下のフォルダを検索し削除します。
- %System Root%\10a0699fa37928d39c
- %Temporary Internet Files%\Content.IE5\2C10A89
手順 8
コンピュータを通常モードで再起動し、最新のバージョン(エンジン、パターンファイル)を導入したウイルス対策製品を用い、「TROJ_VB.BJR」と検出したファイルの検索を実行してください。 検出されたファイルが、弊社ウイルス対策製品により既に駆除、隔離またはファイル削除の処理が実行された場合、ウイルスの処理は完了しており、他の削除手順は特にありません。
手順 9
以下のファイルをバックアップを用いて修復します。なお、マイクロソフト製品に関連したファイルのみ修復されます。このマルウェア/グレイウェア/スパイウェアが同社製品以外のプログラムをも削除した場合には、該当プログラムを再度インストールする必要があります。
- %Desktop%\vcredist_x86.exe
- %Desktop%\WinPcap_4_1_2.exe
- %Program Files%\Common Files\Microsoft Shared\MSInfo\msinfo32.exe
- %Program Files%\Common Files\Microsoft Shared\Speech\sapisvr.exe
- %Program Files%\Internet Explorer\Connection Wizard\icwconn1.exe
- %Program Files%\Internet Explorer\Connection Wizard\icwconn2.exe
- %Program Files%\Internet Explorer\Connection Wizard\icwrmind.exe
- %Program Files%\Internet Explorer\Connection Wizard\icwtutor.exe
- %Program Files%\Internet Explorer\Connection Wizard\inetwiz.exe
- %Program Files%\Internet Explorer\Connection Wizard\isignup.exe
- %Program Files%\Internet Explorer\iedw.exe
- %Program Files%\Internet Explorer\IEXPLORE.EXE
- %Program Files%\Messenger\msmsgs.exe
- %Program Files%\Movie Maker\moviemk.exe
- %Program Files%\MSN\MSNCoreFiles\Install\MSN9Components\Digcore.exe
- %Program Files%\MSN\MSNCoreFiles\Install\MSN9Components\Msncli.exe
- %Program Files%\MSN\MSNCoreFiles\Install\msnsusii.exe
- %Program Files%\MSN Gaming Zone\Windows\bckgzm.exe
- %Program Files%\MSN Gaming Zone\Windows\chkrzm.exe
- %Program Files%\MSN Gaming Zone\Windows\hrtzzm.exe
- %Program Files%\MSN Gaming Zone\Windows\Rvsezm.exe
- %Program Files%\MSN Gaming Zone\Windows\shvlzm.exe
- %Program Files%\MSN Gaming Zone\Windows\zClientm.exe
- %Program Files%\NetMeeting\cb32.exe
- %Program Files%\NetMeeting\conf.exe
- %Program Files%\NetMeeting\wb32.exe
- %Program Files%\Outlook Express\msimn.exe
- %Program Files%\Outlook Express\oemig50.exe
- %Program Files%\Outlook Express\setup50.exe
- %Program Files%\Outlook Express\wab.exe
- %Program Files%\Outlook Express\wabmig.exe
- %Program Files%\Windows Media Player\migrate.exe
- %Program Files%\Windows Media Player\mplayer2.exe
- %Program Files%\Windows Media Player\setup_wm.exe
- %Program Files%\Windows Media Player\wmplayer.exe
- %Program Files%\Windows NT\Accessories\wordpad.exe
- %Program Files%\Windows NT\Pinball\PINBALL.EXE
- %Program Files%\Windows NT\dialer.exe
- %Program Files%\Windows NT\hypertrm.exe
- %Program Files%\WinPcap\rpcapd.exe
- %Program Files%\WinPcap\Uninstall.exe
- %Windows%\Help\Tours\mmTour\tour.exe
- %Windows%\inf\unregmp2.exe
- %Windows%\Installer\{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}\places.exe
手順 10
以下の削除されたレジストリキーまたはレジストリ値をバックアップを用いて修復します。
※註:マイクロソフト製品に関連したレジストリキーおよびレジストリ値のみが修復されます。このマルウェアもしくはアドウェア等が同社製品以外のプログラムも削除した場合には、該当プログラムを再度インストールする必要があります。
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EE09B103-97E0-11CF-978F-00A02463E06F}
- InprocServer32
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EE09B103-97E0-11CF-978F-00A02463E06F}
- TypeLib
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EE09B103-97E0-11CF-978F-00A02463E06F}
- Version
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EE09B103-97E0-11CF-978F-00A02463E06F}
- ProgID
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID
- {EE09B103-97E0-11CF-978F-00A02463E06F}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Scripting.Dictionary
- CLSID
- In HKEY_CLASSES_ROOT
- Scripting.Dictionary
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0D43FE01-F093-11CF-8940-00A0C9054228}
- InprocServer32
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0D43FE01-F093-11CF-8940-00A0C9054228}
- TypeLib
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0D43FE01-F093-11CF-8940-00A0C9054228}
- Version
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0D43FE01-F093-11CF-8940-00A0C9054228}
- ProgID
- In
- {7DD95801-9882-11CF-9FA9-00AA006C42C4}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0D43FE01-F093-11CF-8940-00A0C9054228}
- Implemented Categories
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID
- {0D43FE01-F093-11CF-8940-00A0C9054228}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Scripting.FileSystemObject
- CLSID
- In HKEY_CLASSES_ROOT
- Scripting.FileSystemObject
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{32DA2B15-CFED-11D1-B747-00C04FC2B085}
- InprocServer32
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{32DA2B15-CFED-11D1-B747-00C04FC2B085}
- TypeLib
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{32DA2B15-CFED-11D1-B747-00C04FC2B085}
- Version
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{32DA2B15-CFED-11D1-B747-00C04FC2B085}
- ProgID
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{32DA2B15-CFED-11D1-B747-00C04FC2B085}
- Implemented Categories
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID
- {32DA2B15-CFED-11D1-B747-00C04FC2B085}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Scripting.Encoder
- CLSID
- In HKEY_CLASSES_ROOT
- Scripting.Encoder
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0CF774D0-F077-11D1-B1BC-00C04F86C324}
- ProgID
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0CF774D0-F077-11D1-B1BC-00C04F86C324}
- InprocServer32
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID
- {0CF774D0-F077-11D1-B1BC-00C04F86C324}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\HTML.HostEncode
- CLSID
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0CF774D1-F077-11D1-B1BC-00C04F86C324}
- ProgID
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0CF774D1-F077-11D1-B1BC-00C04F86C324}
- InprocServer32
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID
- {0CF774D1-F077-11D1-B1BC-00C04F86C324}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ASP.HostEncode
- CLSID
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{85131630-480C-11D2-B1F9-00C04F86C324}
- ProgID
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{85131630-480C-11D2-B1F9-00C04F86C324}
- InprocServer32
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID
- {85131630-480C-11D2-B1F9-00C04F86C324}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\JSFile.HostEncode
- CLSID
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{85131631-480C-11D2-B1F9-00C04F86C324}
- ProgID
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{85131631-480C-11D2-B1F9-00C04F86C324}
- InprocServer32
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID
- {85131631-480C-11D2-B1F9-00C04F86C324}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VBSFile.HostEncode
- CLSID
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\htmlfile
- ScriptHostEncode
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\aspfile
- ScriptHostEncode
- In HKEY_CLASSES_ROOT
- aspfile
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\JSFile
- ScriptHostEncode
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VBSFile
- ScriptHostEncode
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{420B2830-E718-11CF-893D-00A0C9054228}\1.0\0
- win32
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{420B2830-E718-11CF-893D-00A0C9054228}\1.0
- FLAGS
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{420B2830-E718-11CF-893D-00A0C9054228}\1.0
- HELPDIR
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{420B2830-E718-11CF-893D-00A0C9054228}
- 1.0
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{42C642C1-97E1-11CF-978F-00A02463E06F}
- ProxyStubClsid
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{42C642C1-97E1-11CF-978F-00A02463E06F}
- ProxyStubClsid32
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{42C642C1-97E1-11CF-978F-00A02463E06F}
- TypeLib
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface
- {42C642C1-97E1-11CF-978F-00A02463E06F}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0AB5A3D0-E5B6-11D0-ABF5-00A0C90FFFC0}
- ProxyStubClsid
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0AB5A3D0-E5B6-11D0-ABF5-00A0C90FFFC0}
- ProxyStubClsid32
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0AB5A3D0-E5B6-11D0-ABF5-00A0C90FFFC0}
- TypeLib
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface
- {0AB5A3D0-E5B6-11D0-ABF5-00A0C90FFFC0}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C7C3F5A1-88A3-11D0-ABCB-00A0C90FFFC0}
- ProxyStubClsid
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C7C3F5A1-88A3-11D0-ABCB-00A0C90FFFC0}
- ProxyStubClsid32
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C7C3F5A1-88A3-11D0-ABCB-00A0C90FFFC0}
- TypeLib
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface
- {C7C3F5A1-88A3-11D0-ABCB-00A0C90FFFC0}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C7C3F5A0-88A3-11D0-ABCB-00A0C90FFFC0}
- ProxyStubClsid
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C7C3F5A0-88A3-11D0-ABCB-00A0C90FFFC0}
- ProxyStubClsid32
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C7C3F5A0-88A3-11D0-ABCB-00A0C90FFFC0}
- TypeLib
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface
- {C7C3F5A0-88A3-11D0-ABCB-00A0C90FFFC0}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C7C3F5A2-88A3-11D0-ABCB-00A0C90FFFC0}
- ProxyStubClsid
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C7C3F5A2-88A3-11D0-ABCB-00A0C90FFFC0}
- ProxyStubClsid32
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C7C3F5A2-88A3-11D0-ABCB-00A0C90FFFC0}
- TypeLib
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface
- {C7C3F5A2-88A3-11D0-ABCB-00A0C90FFFC0}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C7C3F5A3-88A3-11D0-ABCB-00A0C90FFFC0}
- ProxyStubClsid
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C7C3F5A3-88A3-11D0-ABCB-00A0C90FFFC0}
- ProxyStubClsid32
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C7C3F5A3-88A3-11D0-ABCB-00A0C90FFFC0}
- TypeLib
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface
- {C7C3F5A3-88A3-11D0-ABCB-00A0C90FFFC0}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C7C3F5A5-88A3-11D0-ABCB-00A0C90FFFC0}
- ProxyStubClsid
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C7C3F5A5-88A3-11D0-ABCB-00A0C90FFFC0}
- ProxyStubClsid32
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C7C3F5A5-88A3-11D0-ABCB-00A0C90FFFC0}
- TypeLib
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface
- {C7C3F5A5-88A3-11D0-ABCB-00A0C90FFFC0}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C7C3F5A4-88A3-11D0-ABCB-00A0C90FFFC0}
- ProxyStubClsid
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C7C3F5A4-88A3-11D0-ABCB-00A0C90FFFC0}
- ProxyStubClsid32
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C7C3F5A4-88A3-11D0-ABCB-00A0C90FFFC0}
- TypeLib
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface
- {C7C3F5A4-88A3-11D0-ABCB-00A0C90FFFC0}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{53BAD8C1-E718-11CF-893D-00A0C9054228}
- ProxyStubClsid
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{53BAD8C1-E718-11CF-893D-00A0C9054228}
- ProxyStubClsid32
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{53BAD8C1-E718-11CF-893D-00A0C9054228}
- TypeLib
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface
- {53BAD8C1-E718-11CF-893D-00A0C9054228}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2A0B9D10-4B87-11D3-A97A-00104B365C9F}
- ProxyStubClsid
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2A0B9D10-4B87-11D3-A97A-00104B365C9F}
- ProxyStubClsid32
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2A0B9D10-4B87-11D3-A97A-00104B365C9F}
- TypeLib
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface
- {2A0B9D10-4B87-11D3-A97A-00104B365C9F}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{AADC65F6-CFF1-11D1-B747-00C04FC2B085}
- ProxyStubClsid
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{AADC65F6-CFF1-11D1-B747-00C04FC2B085}
- ProxyStubClsid32
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{AADC65F6-CFF1-11D1-B747-00C04FC2B085}
- TypeLib
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface
- {AADC65F6-CFF1-11D1-B747-00C04FC2B085}
ご利用はいかがでしたか? アンケートにご協力ください