This week the people who write SpyFalcon have instead focused on bringing out some new variants for SpywareQuake. As always the SpywareQuake removal instructions have been updated for these variants.
Reg keys for C:\Windows\System32\yhbdupd.dll:
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\
SharedTaskScheduler]
“{aea3d2df-2b2c-4d7b-81a0-d975c6dc088e}”=”alongshore”
[HKEY_CURRENT_USER\Software\Classes\CLSID\
{aea3d2df-2b2c-4d7b-81a0-d975c6dc088e}\InProcServer32]
@=”C:\\WINDOWS\\System32\\yhbdupd.dll”
Reg keys for C:\Windows\System32\imfdfcj.dll:
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\
SharedTaskScheduler]
“{e5b1e382-817e-4b74-8a96-ec78751e6acf}”=”incatenate”
[HKEY_CURRENT_USER\Software\Classes\CLSID\
{e5b1e382-817e-4b74-8a96-ec78751e6acf}\InProcServer32]
@=”C:\\WINDOWS\\system32\\imfdfcj.dll”
Reg keys for C:\Windows\System32\hvnwm.dll:
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\
SharedTaskScheduler]
“{62eb0924-19d2-4226-b4b9-8ad1f70904c1}”=”bronchovascular”
[HKEY_CURRENT_USER\Software\Classes\CLSID\
{62eb0924-19d2-4226-b4b9-8ad1f70904c1}\InProcServer32]
@=”C:\\WINDOWS\\system32\\hvnwm.dll”
Tags: No Tags