In HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Run
Windows\CurrentVersion\Explorer\
Advanced\Folder\Hidden\
SHOWALL
*Note: There may be some component files that are hidden. Please make sure you check the Search Hidden Files and Folders checkbox in the "More advanced options" option to include all hidden files and folders in the search result.
Windows\CurrentVersion\Run
- 54dfsger = "%System%\xvassdf.exe"
- In HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Explorer\
Advanced- From: Hidden = "2"
To: Hidden = "1" - From: ShowSuperHidden = "0"
To: ShowSuperHidden = "1"
- From: Hidden = "2"
Windows\CurrentVersion\Explorer\
Advanced\Folder\Hidden\
SHOWALL
- From: CheckedValue = "0"
To: CheckedValue = "1"
*Note: There may be some component files that are hidden. Please make sure you check the Search Hidden Files and Folders checkbox in the "More advanced options" option to include all hidden files and folders in the search result.
- %System%\4tddfwq0.dll
- %System%\dllcache\cdaudio.sys
[AutoRun] open=jdwwl.exe shell\open\Command=jdwwl.exe
Credit : Trend Micro
http://threatinfo.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_TATERF.CX&VSect=Sn
============================================================