unixfreaxjp wrote: This malware was detected below software/program/service.. suspected registry token keys.Explanation starting from this page http://www.kernelmode.info/forum/viewto ... &start=110 and down.Code: Select allThe reason is for deletion purpose, I found many stuffs deleted in registry like:Windows Defender wscntfy.exe MSASCui.exe MpCmdRun.exe NisSrv.exe msseces.exe fp.exe MsMpSvc windefend SharedAccess iphlpsvc wscsvc mpssvc (etc)
Code: Select all..\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy ..\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile ..\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications ..\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List ..\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile ..\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications ..\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List ..\System\CurrentControlSet\Services\SharedAccess\Setup ..\System\CurrentControlSet\Services\SharedAccess\Setup\InterfacesUnfirewalledAtUpdate ..\System\CurrentControlSet\Services\wscsvc ..\System\CurrentControlSet\Services\wscsvc\Enum ..\System\CurrentControlSet\Services\wscsvc\Parameters ..\System\CurrentControlSet\Services\wscsvc\Security
Posts moved.
Ring0 - the source of inspiration