Quantcast
Channel: Sysinternals Forums
Viewing all articles
Browse latest Browse all 10386

Malware : KRECWLENUZWGAI entry in registry - suspicious

$
0
0
Author: wazon
Subject: KRECWLENUZWGAI entry in registry - suspicious
Posted: 30 July 2013 at 12:47pm

Yeah I know now. Also it created service with same name and it was in HKEY_LOCAL_MACHINE\System\ControlSet001\Services\KRECWLENUZWGAI and HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\KRECWLENUZWGAI\ I've also found HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\TLDOEVYJKEN - it's probably the same instance of this crap.
 
They all were placed in C:\Users\User_Name\AppData\Local\Temp\ for a while. Hope I didn't get some firmware malware..

Viewing all articles
Browse latest Browse all 10386

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>