Microsoft Windows Vista SP2, All other registered and unregistered trademarks represented in this document are the sole property of their respective companies/owners. FULLDISC:20160210 NPS Datastore server DLL side loading vulnerability URL:http://seclists.org/fulldisclosure/2016/Feb/49 MISC:https://www.securify.nl/advisory/SFY20150905/nps_datastore_server_dll_side_loading_vulnerability.html MS:MS16-009 URL:http://technet.microsoft.com/security/bulletin/MS16-009 MS:MS16-014 URL:http://technet.microsoft.com/security/bulletin/MS16-014 SECTRACK:1034971 URL:http://www.securitytracker.com/id/1034971 SECTRACK:1034985 URL:http://www.securitytracker.com/id/1034985

TECHNICAL DETAILS File Size: 44,800 bytesFile Type: EXEMemory Resident: NoInitial Samples Received Date: 08 Dec 2012 In HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\Main DEPOff = "1" In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows CrntDLL = "%System%\0041.DLL" In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows LoadAppInit_DLLs = "1" To delete the registry value this malware/grayware created: Open Registry Editor.

In HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer Main To delete the registry key this malware/grayware created: Open Registry Editor.

Microsoft Internet Explorer 10 Microsoft Internet Explorer 11 Microsoft Windows 10 for 32-bit Systems Microsoft Windows 10 for x64-based Systems Microsoft Windows 10 version 1511 for 32-bit Systems

Microsoft Windows 8.1 for x64-based Systems 0 Microsoft Security Update for Windows 8.1 for x64-based Systems (KB3126434) https://www.microsoft.com/downloads/details.aspx?familyid=759c253f-41b 4-4cac-98b9-fc8f0513821e Microsoft Security Update for Windows 8.1 for x64-based Systems (KB3126587) https://www.microsoft.com/downloads/details.aspx?familyid=a6fbab67-827 e-441a-a8e8-029ccf047e8b

