Acquisition time :2010-5-26
Risk level: Medium
virus symptoms:
The sample is the trojan downloader prepared by “VC”, size, “1,489,408″ bytes, the icon is “
“, Virus extension” exe “, mainly through the” removable storage media “,” file bundle “,” download manager “,” page linked to race “, etc., the viruses main purpose is to download and run the virus.
After the user’s computer was infected, the system will appear to run Slow, the network slows down, system error for no reason, a large number of unknown processes, anti-virus software can not start, can not enter safe mode and so on.
Infected object:
Windows 2000/Windows XP / Windows 2003/Windows Vista / Windows 7
Transmission:
Removable storage media, Web Trojans, file bundle, download manager
Manually delete method:
1. Replace the following documents with a normal system file:
% SystemRoot% \ system32 \ appmgmts.dll
% SystemRoot% \ system32 \ drivers \ etc \ hosts
2. Note the table with the normal values into the following location:
HKEY_LOCAL_MACHINE \ SYSTEM \ ControlSet001 \ Control \ SafeBoot
HKEY_LOCAL_MACHINE \ SYSTEM \ ControlSet001 \ Control \ Network
Variable declaration:
% SystemDriver% system where the partition, typically “C: \”
% SystemRoot% WINDODWS directory, usually “C: \ Windows”
% Documents and Settings% user documentation directory, usually “C: \ Documents and Settings”
% Temp% temp folder, usually “C: \ Documents and Settings \ current user name \ Local Settings \ Temp”
% ProgramFiles% system program default installation directory, typically: “C: \ ProgramFiles”
The virus creates a file:
% SystemRoot% \ DelInfo.bin
% SystemRoot% \ booter.exe
% SystemRoot% \ system32 \ appmgmts.dll
X: \ autorun.inf (X is the letter of the infected disk)
X: \ recycle. (645FF040-5081-101B-9F08-00AA002F954E) \ Setup.exe
Virus delete the file:
% SystemRoot% \ DelInfo.bin
% SystemRoot% \ booter.exe
Viruses modify the file:
% SystemRoot% \ system32 \ appmgmts.dll
% SystemRoot% \ system32 \ drivers \ etc \ hosts
HKEY_LOCAL_MACHINE \ SYSTEM \ ControlSet001 \ Control \ SafeBoot
HKEY_LOCAL_MACHINE \ SYSTEM \ ControlSet001 \ Control \ Network
Somebody necessarily assist to make significantly posts I’d state. That is the very first time I frequented your website page and so far? I amazed with the analysis you made to create this particular publish amazing. Excellent activity!
Nice article, will subscribe for now and wait for some more =)
Links…
[...]Sites of interest we have a link to[...]……
Hey……
I’ve recently started a web site, the information you offer on this site has helped me greatly. Thank you for all of your time & work. “You do ill if you praise, but worse if you censure, what you do not understand.” by Leonardo DaVinci….
Read was interesting, stay in touch……
[...]please visit the sites we follow, including this one, as it represents our picks from the web[...]……
Websites we think you should visit…
[...]although websites we backlink to below are considerably not related to ours, we feel they are actually worth a go through, so have a look[...]……
News info…
I was reading the news and I saw this really interesting topic…
Recommendations…
One spot which I possibly could suggest for addional details….
Giving thanks…
We must be happy for this….
Online Article……
[...]The information mentioned in the article are some of the best available [...]……
Medical Marijuana Dispensaries…
[...]the time to read or check out the content or pages we have linked to below the[...]…
Medical Marijuana Dispensaries…
[...]the time to read or visit the content or places we have linked to underneath the[...]…
Sources…
[...]check below, are some totally unrelated websites to ours, however, they are most trustworthy sources that we use[...]……
Visitor recommendations…
[...]one of our visitors recently recommended the following website[...]……
Hello…..
Thank you for sharing superb informations. Your website is very cool. I am impressed by the details that you have on this web site. It reveals how nicely you perceive this subject. Bookmarked this web page, will come back for more articles. You, my fri…
zonBuyer.com…
zonBuyer.com lets you find the hottest deals on the amazon right now. With it’s easy to use one-click shopping cart, you can order your desired items in seconds….
Could have been worse…
Would have rather let my honey wax my eyebrows….
Websites you should visit…
[...]below you’ll find the link to some sites that we think you should visit[...]……