|
Common Start Up Routines Of Trojan Viruses
Autoexec.bat (MS-DOS) Win.ini
[windows] load= run=
System.ini
[boot] Shell=Explorer.exe trojan.exe
Autostart folder (not often used by trojans, because it is to easy to look up and remove) Registry [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunServices] c:\windows\wininit.ini
|
|