Recently, the APT attack virus (Flame) is surging. Based on the analysis of the virus sample, Kaspersky Lab provides a method to quickly detect whether your system has been infected with Flame.
1. Find the file ~ DEB93D. tmp. If such a file exists in the system, it means it has been infected with Flame. 2. Check the registry key HKLM_SYSTEM \ CurrentControlSet \ Control \ Lsa \ Authentication Packages. If you find mssecmgr. ocx or authpack. ocx, your device has been infected with Flame. 3. check whether the following logs exist. If yes, the logs are infected: C: \ Program Files \ Common Files \ Microsoft Shared \ MSSecurityMgrC: \ Program Files \ Common Files \ Microsoft Shared \ MSAudioC: \ Program Files \ Common Files \ Microsoft Shared \ MSAuthCtrlC: \ Program Files \ Common Files \ Microsoft Shared \ MSAPackagesC: \ Program Files \ Common Files \ Microsoft Shared \ MSSndMix4. find other file names mentioned above. These file names are very special and unique. If they exist, they are very likely to have been infected with Flame.