trojan downloader: Trojan-Downloader.Win32.FraudLoad.ped
Risk level: Medium
virus Description
The virus extension “exe”, mainly through “file bundle”, “Download Tools”, “page linked to horse” etc. to spread, the primary purpose of viruses is to download malicious programs to the user’s computer to run.
When the user’s computer is infected, there will be computer and network running Slow, slow systems and networks, the program shut down for no reason, there kinds of viruses, which leads to user privacy disclosure.
Infected OS
Windows 2000/Windows XP / Windows 2003/Windows Vista / Windows 7
Manual Solution:
1, manually delete the following files:
C: \ RECYCLER \ S-1-5-21-0243936033-3052116371-381863308-1811 \ vsbntlo.exe
C: \ RECYCLER \ S-1-5-21-0243936033-3052116371-381863308-1811 \ Desktop.ini
2, manually delete the following Registry key:
HKEY_CURRENT_USER \ Software \ Microsoft \ Windows \ CurrentVersion \ Run
Name: 12CFG214-K641-12SF-N85P
Data: C: \ RECYCLER \ S-1-5-21-0243936033-3052116371-381863308-1811 \ vsbntlo.exe
Variable declaration:
% SystemDriver% system where the partition, usually “C: \”
% SystemRoot% WINDODWS directory, usually “C: \ Windows”
% Documents and Settings% user file directory, usually “C: \ Documents and Settings”
% Temp% temp folder, usually “C: \ Documents and Settings \ current user name \ Local Settings \ Temp”
% ProgramFiles% system program the default installation directory, typically: “C: \ ProgramFiles”
Virus to create files:
C: \ RECYCLER \ S-1-5-21-0243936033-3052116371-381863308-1811 \ vsbntlo.exe
C: \ RECYCLER \ S-1-5-21-0243936033-3052116371-381863308-1811 \ Desktop.ini
Virus creates registry entries:
HKEY_CURRENT_USER \ Software \ Microsoft \ Windows \ CurrentVersion \ Run
Name: 12CFG214-K641-12SF-N85P
Data: C: \ RECYCLER \ S-1-5-21-0243936033-3052116371-381863308-1811 \ vsbntlo.exe
Virus to access the network:
p34s3 .***. com
Kiteboarding News…
[...]below you’ll find the link to some sites that we think you should visit[...]…
Online Article……
[...]The information mentioned in the article are some of the best available [...]……
bra kattmat…
[...]g This is is great. You’re a very professional blogger. I’ve joined your dg[...]…
länkar till paris…
[...]b What cache product do you use for this website? It loads so much faster tha dw[...]…
mina pormaskar försvann…
[...]n Very few blogs that happen to be detailed below, from our point of view are ou[...]…
berlin potsdamer platz…
[...]u Just added this website to my bookmarks. I enjoy reading your websites and ke[...]…
shoppa outlets paris…
[...]5 I am visiting this place for the first time. I have come to know a lot of i bj[...]…
acne laser nytt collagen…
[...]a I am visiting this place for the first time. I have come to know a lot of i 0v[...]…
vad orsakar akne…
[...]t Very few sites that happen to be detailed below, from our point of view are m9[...]…
perfekt konkurrens…
[...]f What cache product do you use for this website? It loads so much faster tha xz[...]…
väder paris oktober…
[...]v I am visiting this place for the first time. I have come to know a lot of i dj[...]…
above the influence…
Hey very nice blog!!. Of course, what a magnificent website and illuminating posts, I definitely will bookmark your site.Best Regards! more please more please….
diş…
estetik…
ukash…
ukash kart…
prefabrik…
konteyner…
birleşim konteyner…
konteyner teknik bilgileri…
emlak…
emlak ilanlari…
sceptral nice for den…
dentist is nice…
müzikforum…
müzik forum…
Cazibeli resim…
Cazbeli resimler…
film izle…
dizi izle…
engagement rings…
wedding rings…
toptan mallar…
toptan mallar…
aspirinn…
hugebody…