http://www.microsoft.com/security/porta ... n32/Medfos
Some examples:
Some examples:
Code: Select all
HKU\Owner\...\Run: [AVG Secure Search] rundll32.exe "C:\Users\Owner\AppData\Local\Broadcom\AVG Secure Search\zjfdkvut.dll",fltInfoW [334848 2012-10-23] (Microsoft Corporation)
Code: Select all
O4 - HKCU..\Run: [Moss Bay Software] C:\Users\Owner\AppData\Local\Moss Bay Software\iidjqzga.dll (Dolby Technology)
Code: Select all
[2012/10/02 19:32:14 | 000,000,000 | ---D | M] (Mozilla Safe Browsing) -- C:\USERS\Owner\APPDATA\LOCAL\{6250848E-0CE9-11E2-8271-B8AC6F996F26}
Code: Select all
C:\Users\Owner\AppData\Local\{39D6B3A6-F2CF-11E1-8270-B8AC6F996F26}\chrome\content\browser.xul JS/Redirector.NIQ trojan cleaned by deleting - quarantined