• Home
  • Regtweaker
  • Subscribe to Posts
  • Subscribe to comments

PC solutions

Give you Professional Suggestions

  • Home
  • News
  • Registry
  • Script
  • System Utility
  • Virus
  • Windows
  • XML
Home Virus manually remove Backdoor: Rootkit.Win32.Agent.a

manually remove Backdoor: Rootkit.Win32.Agent.a

Posted on Saturday, 24 July 2010
309 Comments
Share|

backdoor: Rootkit.Win32.Agent.a

Risk level: Medium

virus Description

The sample is a “back doors” program which was developed by the “VC”, with “UPX” way of trying to evade signature scanning packers, packers after the size of “37,376″ bytes, the icon for the “remove backdoor“, use the “exe” extension, through the file bundle, page trojan, download tools to download, etc. and spread. The main purpose is to control the virus, the user’s computer. When the user’s computer is infected with this virus, there will be no reason the system error, anti-virus software does not start automatically quit and found a large number of unknown processes and so on.

Infected OS

Windows 2000/Windows XP / Windows 2003/Windows Vista / Windows 7

Transmission

File bundle, page trojan, download tools to download

Manual Solution:

Manually delete files

1. Deleted% SystemRoot% \ system32 \ ZGu.dll
2. Deleted% SystemRoot% \ system32 \ drivers \ ietg.sys

Manually delete the Registry

1. Remove the HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Services \ Ietg

Variable declaration:

% SystemDriver% system where the partition, typically “C: \”
% SystemRoot% WINDODWS directory, usually “C: \ Windows”
% Documents and Settings% user documentation directory, usually “C: \ Documents and Settings”
% Temp% temp folder, usually “C: \ Documents and Settings \ current user name \ Local Settings \ Temp”
% ProgramFiles% system program default installation directory, typically: “C: \ ProgramFiles”

Virus analysis:

1. The virus access to the system directory, created file directory% SystemRoot% \ system32 \ ZGu.dll in the system.
2. Loading% SystemRoot% \ system32 \ ZGu.dll, create a keyboard and mouse message hook, monitor user information.
3. Create file batch% SystemDriver% \ Ck7YjX.bat, self-delete.
4.% SystemRoot% \ system32 \ drivers \ Ietg.sys create driver services, and registry keys HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Services \ Ietg, for self-starting.
5. To create the specified thread links hacker network, the user machine’s processor type, operating system version, operating system, the default language and other information sent to the hacker specified URL. And wait for further orders hackers.

The virus creates a file:

% SystemRoot% \ system32 \ ZGu.dll (random name)
% SystemRoot% \ system32 \ drivers \ Ietg.sys
% SystemDriver% \ Ck7YjX.bat

Virus to create the registry:

HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Services \ Ietg
Name: IMAGEPATH
Data: System32 \ drivers \ IETG.sys

Virus access to the network:

http://www .****. com.cn / update.php?
http://www .****. com.cn / api.php?


Share this Post:
Digg Google Bookmarks reddit Mixx StumbleUpon Technorati Yahoo! Buzz DesignFloat Delicious BlinkList Furl
Tagged with: Backdoor, Backdoor Rootkit.Win32.Agent.a, remove Rootkit.Win32.Agent.a

309 Responses to “manually remove Backdoor: Rootkit.Win32.Agent.a”

Trackbacks are disabled.

leather boots
boat insurance
Lethal Commission
one new man
Best Elliptical for Home Use
Air Swimmers
Tap Pet Hotel Coins
777 Poker Game Betting
scottsdale acupuncture
Puss In Boots Full Movie
Ironman 4000 Inversion Table
Wicked Spice
business card maker
find players
Watch A Very Harold and Kumar Christmas
Can I Retire
Watch A Very Harold and Kumar Christmas
spiritual healing
zojirushi home bakery supreme breadmaker
Watch The Rum Diary Online
schwinn 420 elliptical
garmin for runner
s5211 miele
custom writing
Watch The Rum Diary Online
particulier credit
A Very Harold and Kumar Christmas Full Movie
A Very Harold and Kumar Christmas Full Movie
Watch The Rum Diary Online
free ebooks
horizon treadmill
Robin Sorensen
where to buy phen375
jet ski insurance
outdoor climbers
get rid of acne scars
Blackheads
Jocuri fete
How to get rid of blackheads
Front Core Capital Gold Market
k2 incense
name
url
fire and water damage
gps tracker for car
Koh Chang Information
farmville cheat codes
Kids Eat Free Tuesday
click here to continue
Volunteer Uganda Medical Nurse Programs
hoover electric broom
Kristina Concho
Ashley Scott
Accounting Basics
Accounting Basics
astrologie 2012
Hotels for All
9500ci Passport Radar Detector
cheshire pat testing
Statesville Ice Cream
how to fight depression
Thrifty Car Rental Coupon Code
Statesville Ice Cream
Accounting Basics
Statesville Ice Cream
Watch 11-11-11 Online
Statesville Ice Cream
866-826-4101
Accounting Basics
Asian Tiger Mosquito
Twilight Breaking Dawn FULL MOVIE
special education california
unemployment extensions
Projector Reviews
Twilight Breaking Dawn FULL MOVIE
new music
Twilight Breaking Dawn FULL MOVIE
Accounting Basics
braces lakeville
water conservation tips
water conservation gifts
skin care products
water softener
Twilight Breaking Dawn FULL MOVIE
online bidding
security essentials
Twilight Breaking Dawn FULL MOVIE
Web design company spring Houston
photos paintings
betainvites.com
Habit? Game titles Crewed out boy’s real life
payless shoes coupon code
ReADY LIFT kit
best home elliptical
wheels FINancing
Staycation Holiday
vinegar uses
corporate photographer
Samsung unlocking
Facebookpasswordhack
Asian Tiger Mosquito
Asian Tiger Mosquito
Asian Tiger Mosquito
Asian Tiger Mosquito
Asian Tiger Mosquito
Asian Tiger Mosquito
Asian Tiger Mosquito
brainwave entrainment free
after a heart attack
fontanny czekoladowe
Accounting Basics
Accounting Basics
TI-83 calculator
kindle 3g review
fontanny czekoladowe
Asian Tiger Mosquito
Accounting Basics
carrera endurance
solbriller
bvlgari sunglasses
folia
Accounting Basics
Firehouse Subs
  • razor electric scooters says:
    2012-02-29 at 7:00 am

    You recognize thus significantly when it comes to this matter, made me individually imagine it from numerous numerous angles. Its like men and women aren’t interested except it is something to accomplish with Woman gaga! Your own stuffs great. At all times take care of it up!

  • ITIL certification says:
    2012-02-29 at 6:46 am

    Thank you a bunch for sharing this with all people you actually recognise what you are talking approximately! Bookmarked. Kindly additionally talk over with my site =). We can have a hyperlink change agreement between us

  • WoW Gold kaufen says:
    2011-10-23 at 3:46 pm

    WoW Gold kaufen…

    [...]Every as soon as in a when we choose blogs that we study. Listed beneath would be the latest websites that we choose [...]…

  • Final Countdown says:
    2011-10-16 at 7:28 pm

    2011…

    F*ckin’ awesome things here. I’m very glad to see your post. Thanks a lot and i am looking forward to contact you. Will you kindly drop me a e-mail?…

  • test says:
    2011-10-15 at 6:08 pm

    Must Read For All Who Like Affiliating…

    [...]When you know when doing your work you can do a lot more than when you have no skills…..

  • singles dating sites says:
    2011-10-11 at 12:52 pm

    top dating sites…

    These people can certainly control you ones own existence through thier outcome….

  • free date sites says:
    2011-10-11 at 6:34 am

    100 free dating sites…

    Check this out……

  • La Jolla and San Diego CA Homes For Sale says:
    2011-10-7 at 7:51 am

    www.eRealEstateLaJolla.com…

    Search Ca homes for sale using our La Jolla and San Diego MLS real estate search. Receive email updates of Realtor listings with prices and blog for all your San Diego county real estate needs. Whether single-family houses, townhomes, luxury homes, bea…

  • symptoms of heartburn and indigestion says:
    2011-10-5 at 3:44 am

    heartburn and indigestion…

    Websites worth visiting……

  • cure for heartburn says:
    2011-10-4 at 7:35 pm

    natural heartburn relief…

    we like to honor many other internet sites on the web, even if they aren๏ฟฝt linked to us, by linking to them. Under are some webpages worth checking out…

  • Comment Avoir Un Ventre Plat Rapidement says:
    2011-10-1 at 10:19 pm

    2011…

    Great wordpress blog here.. It’s hard to find quality writing like yours these days. I really appreciate people like you! take care…

  • Buy Targeted Fb Fans says:
    2011-09-30 at 4:00 pm

    Super Website…

    [...] that is the end of this article. Here you’ll find some sites that we think you’ll appreciate, just click the links over[...]…

  • Symptoms Of Low Vitamin D says:
    2011-09-29 at 11:25 pm

    Symptoms Of Low Vitamin D…

    please visit the sites we follow, including this one, as it represents our picks from the web…

  • Ways To Make Money says:
    2011-09-28 at 11:12 am

    2011…

    Thanks for sharing excellent informations. Your site is so cool. I am impressed by the details that you have on this site. It reveals how nicely you understand this subject. Bookmarked this web page, will come back for extra articles. You, my pal, ROCK…

  • San Diego homes for sale says:
    2011-09-27 at 9:06 pm

    www.eRealEstateSanDiego.com…

    Pacific Real Estate Broker serving all of your San Diego county real estate needs. Search Ca homes for sale using our MLS search. Receive email updates of Realtor listings with prices and blog. Whether single-family houses, townhomes, luxury homes, bea…

  • Japanese Calligraphy says:
    2011-09-25 at 10:47 am

    OH HAI…

    Valuable information. Lucky me I found your website by accident, and I’m shocked why this accident did not happened earlier! I bookmarked it….

  • Iron Deficiency Symptoms says:
    2011-09-25 at 9:59 am

    OH HAI…

    I’d have to examine with you here. Which is not one thing I usually do! I take pleasure in reading a post that may make folks think. Additionally, thanks for permitting me to comment!…

  • Heartburn During Pregnancy says:
    2011-09-25 at 9:38 am

    OH HAI…

    Just wish to say your article is as astonishing. The clearness in your post is simply excellent and i can assume you are an expert on this subject. Well with your permission let me to grab your RSS feed to keep up to date with forthcoming post. Thanks …

  • Asian Tiger Mosquito says:
    2011-09-25 at 9:18 am

    OH HAI…

    I have been absent for some time, but now I remember why I used to love this web site. Thank you, I’ll try and check back more frequently. How frequently you update your web site?…

  • open says:
    2011-09-23 at 9:14 pm

    OH HAI…

    What’s Happening i am new to this, I stumbled upon this I’ve found It positively helpful and it has helped me out loads. I hope to contribute & aid other users like its aided me. Great job….

  • Iron Deficiency Anemia Symptoms says:
    2011-09-23 at 12:15 am

    OH HAI…

    I got good info from your blog…

  • tennis club says:
    2011-09-22 at 8:42 pm

    tennis club…

    [...]we like to honor a lot of other web websites on the net, even if they aren?t linked to us, by linking to them. Beneath are some webpages really worth checking out[...]…

  • Yosho says:
    2011-09-22 at 11:51 am

    OH HAI…

    Thanks, I’ve recently been searching for information about this subject for ages and yours is the greatest I have discovered so far. But, what about the bottom line? Are you sure about the source?…

  • bulldog for sale says:
    2011-09-20 at 11:07 pm

    bulldog for sale…

    [...]please pay a visit to the web-sites we stick to, including this a single, as it represents our picks in the web[...]…

  • trans says:
    2011-09-20 at 9:11 pm

    trans…

    [...]below you?ll obtain the link to some sites that we think you should visit[...]…

  • video porno says:
    2011-09-20 at 8:08 pm

    video porno…

    [...]we like to honor several other world-wide-web websites around the net, even though they aren?t linked to us, by linking to them. Underneath are some webpages worth checking out[...]…

  • Google says:
    2011-09-16 at 9:02 am

    Google…

    [...]below you?ll find the link to some web-sites that we assume you ought to visit[...]…

  • healthy peanut butter cookies says:
    2011-08-22 at 8:57 pm

    You should check this out……

    [...] Wonderful story, reckoned we could combine a few unrelated data, nevertheless really worth taking a look, whoa did one learn about Mid East has got more problerms as well [...]………

  • شرائح للاتصال الدولي التوأم للكميات فقط ولتجار says:
    2011-08-19 at 10:22 am

    نصل باعلانك الى فضائات لاتتخيلها راسلنا لنشر روابط موقعك في 10000 مدونة…

    Auto Trackback By http://bit.ly/nOtUqT ترافيك اب…

  • canlı maç izle says:
    2011-08-15 at 5:31 am

    iddaa tahminleri…

    spor oyunları…

  • superbahis giriş says:
    2011-08-14 at 8:44 am

    ukash kart…

    ukash…

  • ukash kart says:
    2011-08-14 at 4:53 am

    ukash kart…

    ukash…

  • borsa says:
    2011-08-9 at 5:16 am

    borsa…

    borsa haberleri…

  • h-c-g says:
    2011-08-7 at 5:04 pm

    h-c-g…

    Super day for blogging….

  • Como tocar una guitara says:
    2011-08-5 at 6:06 pm

    Como tocar la guitara…

    Aprender a tocar la guitara electrica…

  • polyester depo says:
    2011-08-2 at 4:48 am

    polyester depo…

    zeytin turşu deposu…

  • « Previous 1 2 3 4

    Leave a Reply:

    Click here to cancel reply.

    Name (required):
    Mail (will not be published) (required):
    Website:
    Comment (required):
    XHTML: You can use these tags: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>
    验证图片
    刷新验证码
    *

    Popular Articles

      • How to uninstall pc optimizer pro, pc optimizer pro removal 1139 comment(s)
      • what is Pbupdate.exe and how to fix Pbupdate.exe error? 1138 comment(s)

    latest comments

    • 正在加载...

    Tags

      Antivirus Suite Autorun ave.exe Backdoor Backdoor.Win32 Backdoor.Win32 removal browser home page was altered cc Clicker.dj Clunky Backdoor removal Default home page is modified DLL files error DOMDocument->load() downloader encountered Fix Kernel32 Dll Error MAC Microsoft Security Essentials PSW PSW.Kykymber.cc registry was modified remove MyWinLocker remove regedit32.exe remove safedrv.exe remove Trojan.Win32.Buzus.a Run command slow computer Speed Up Computer speed up pc Trojan Trojan-Downloader.Win32.Small.b removal Trojan-PSW.Win32 Trojan.Win32 Trojan.Win32 removal Trojan Downloader Trojan Dropper uninstall MyWinLocker variant dj Virus W32.Cervivec.A@mm Win32 Win32.Hack.GrayBird.al.761856 Win32.TrojDownloader.Guupk.ps Worm Worm.Win32

    Category

    • News
    • Others
    • Registry
    • Script
    • System Utility
    • Virus
    • Windows
    • XML

    Archives

    • December 2011
    • November 2011
    • October 2011
    • September 2011
    • July 2011
    • June 2011
    • May 2011
    • April 2011
    • March 2011
    • February 2011

    Links

    • Download Drivers

    Pages

    • Regtweaker
    • Spyware Cease
    
    Copyright © 2012 PC solutions. Powered by VersionHunter.com. registry repair |Threats Center
    Top