• Home
  • Regtweaker
  • Subscribe to Posts
  • Subscribe to comments

PC solutions

Give you Professional Suggestions

  • Home
  • News
  • Registry
  • Script
  • System Utility
  • Virus
  • Windows
  • XML
Home Virus Windows Manually remove Trojan-Clicker.Win32.Agent.dca

Manually remove Trojan-Clicker.Win32.Agent.dca

Posted on Sunday, 12 June 2011
36 Comments
Share|

Agent trojan Click Tools: Trojan-Clicker.Win32.Agent.dca

Risk level: Medium

virus Description

The virus sample size “195,584 bytes”,  icon “Trojan-Clicker.Win32.Agent.dca” , virus extension “exe”, it is mainly through the “file bundle”, “web page linked to horse”, “download tool to download” ways to spread , The main purpose is to use a browser to access the hacker designated site, and intermittent click on the ads. After the user’s computer was infected, there will be computer and network running  Slow.

Infection in the operating system
Windows 2000/Windows XP / Windows 2003/Windows Vista / Windows 7

Transmission

Bundle file, web page linked to horse, download tools to download

Manual Solution:

1, manually delete the following files:
% Documents and Settings% \ ADMINI ~ 1 \ LOCALS ~ 1 \ Temp \ Cookies \ index.dat
% SystemRoot% \ dxplore.exe ”

2, manually delete the following Registry key:
HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Windows \ CurrentVersion \ Run -> “Document explorer” = “C: \ WINDOWS \ dxplore.exe? LC: \ WINDOWS \ dxplore.exe
HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Windows \ CurrentVersion \ Run -> NULL = NULL

Variable declaration:

% SystemDriver% system where the partition, usually “C: \”
% SystemRoot% WINDODWS directory, usually “C: \ Windows”
% Documents and Settings% user file directory, usually “C: \ Documents and Settings”
% Temp% temp folder, usually “C: \ Documents and Settings \ current user name \ Local Settings \ Temp”
% ProgramFiles% system program the default installation directory, typically: “C: \ ProgramFiles”

Analysis of the virus

1. To create links to port 1605 socket;
2. Open the% SystemRoot% \ WindowsShell.Manifest file. Trojan monitors the process to create the process itself;
3. For the% Documents and Settings% \ Administrator \ Local Settings under History; Temporary; and the properties of a series of operations IE5.0;
4. Create the file% Documents and Settings% \ ADMINI ~ 1 \ LOCALS ~ 1 \ Temp \ Cookies \ index.dat;
5 create the file% SystemRoot% \ dxplore.exe “and then replaced with copies of the way to talk about Trojan copies itself deplore.exe;
7. To create the registry startup key HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Windows \ CurrentVersion \ Run -> “Document explorer” = “C: \ WINDOWS \ dxplore.exe? LC: \ WINDOWS \ dxplore.exe” and HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Windows \ CurrentVersion \ Run -> NULL = NULL;
8. Norcox.com connecting to a remote network and from the “http://norcox.com/meet/rss.php?source=ag & just = px download% SystemRoot% \ dxsplor.tst to the local and set the property to hide the running at the same time dxsplor.tst be replaced with dxplore.exe;
9. Access 193.218.156.30:80 download the file to% Documents and Settings% \ ADMINI ~ 1 \ LOCALS ~ 1 \ Temp \ TemporaryInternet Files \ Content.IE5 \ CVG181MX \ rss [1]. Php hijacked browser at startup load itself;

Virus to create a file:

% Documents and Settings% \ ADMINI ~ 1 \ LOCALS ~ 1 \ Temp \ Cookies \ index.dat
% SystemRoot% \ dxplore.exe ”

Virus to create the registry:

HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Windows \ CurrentVersion \ Run -> “Document explorer” = “C: \ WINDOWS \ dxplore.exe? LC: \ WINDOWS \ dxplore.exe
HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Windows \ CurrentVersion \ Run -> NULL = NULL


Share this Post:
Digg Google Bookmarks reddit Mixx StumbleUpon Technorati Yahoo! Buzz DesignFloat Delicious BlinkList Furl
Tagged with: Trojan-Clicker, Trojan-Clicker.Win32, Win32

36 Responses to “Manually remove Trojan-Clicker.Win32.Agent.dca”

Trackbacks are disabled.

Kreuzberg
väder shanghai vinter
missbruk beroende
beyaz
tinnitus kit
  • fakta hongkong says:
    2011-10-2 at 2:41 am

    fakta hongkong…

    [...]o What cache solution do you use for this site? It loads so much faster than pi[...]…

  • definition oligopol says:
    2011-09-30 at 2:14 am

    definition oligopol…

    [...]9 I need to set up wordpess through a webhost. I know i have to download word cp[...]…

  • volar hongkong says:
    2011-09-29 at 9:26 am

    volar hongkong…

    [...]b I am visiting this land for the first time. I have come to know a lot of in xm[...]…

  • anonyma alkoholister historia says:
    2011-09-29 at 5:03 am

    anonyma alkoholister historia…

    [...]t This is is great. You’re a very professional writer. I’ve joined your f aa[...]…

  • studera i kina says:
    2011-09-28 at 3:14 pm

    studera i kina…

    [...]o I am visiting this land for the first time. I have come to know a lot of in ip[...]…

  • shanghai 2012 says:
    2011-09-28 at 1:05 pm

    shanghai 2012…

    [...]b I need to set up wordpess through a webhost. I know i have to download word bo[...]…

  • billiga flygbiljetter hkg says:
    2011-09-28 at 9:15 am

    billiga flygbiljetter hkg…

    [...]1 I am visiting this country for the first time. I have come to know a lot of bg[...]…

  • länkar till paris says:
    2011-09-28 at 6:02 am

    länkar till paris…

    [...]s I am visiting this country for the first time. I have come to know a lot of gc[...]…

  • isme özel hediyeler says:
    2011-09-17 at 9:50 pm

    pratikhediye.com…

    Hi there, You’ve done a fantastic job. I will certainly digg it and personally recommend to my friends. I am sure they’ll be benefited from this site….

  • Xnetwork says:
    2011-09-9 at 8:20 am

    xnetworkegitim.com…

    Hey there, You have done a great job. I’ll definitely digg it and personally suggest to my friends. I’m sure they’ll be benefited from this web site….

  • sarki sözü says:
    2011-09-9 at 12:46 am

    xmp3x.org…

    Hey there, You have done a great job. I will definitely digg it and personally recommend to my friends. I am sure they will be benefited from this site….

  • iddaa tahminleri says:
    2011-08-31 at 8:16 pm

    iddaa sonuçları…

    spor haberleri…

  • film seyret says:
    2011-08-30 at 5:04 am

    online izle…

    Hello there, You’ve done a fantastic job. I’ll certainly digg it and personally suggest to my friends. I am sure they will be benefited from this site….

  • film videoları says:
    2011-08-28 at 8:02 am

    tv videoları…

    Fragman izle…

  • online maç izle says:
    2011-08-15 at 6:11 am

    iddaa programı…

    canlı maç izle…

  • film izle says:
    2011-08-14 at 10:40 am

    filmi izle…

    film izle…

  • ukash says:
    2011-08-14 at 6:29 am

    superbahis…

    superbahis giriş…

  • istanbul Evden Eve Nakliyat says:
    2011-08-11 at 8:18 am

    istanbul Evden Eve Nakliyat…

    Evden Eve Nakliyat…

  • Macera filmi izle says:
    2011-08-11 at 6:21 am

    Aksiyon filmi izle…

    Macera filmi izle…

  • lumix waterproof camera says:
    2011-08-9 at 8:20 am

    lumix waterproof camera…

    waterproof camera…

  • borsa says:
    2011-08-9 at 3:48 am

    borsa…

    borsa haberleri…

  • plastik dik depo says:
    2011-08-5 at 7:50 am

    polyester su deposu…

    plastik dik depo…

  • hd film izle says:
    2011-07-28 at 6:04 am

    film izle…

    http://www.xfilm-izle.com/…

  • müzikforum says:
    2011-07-28 at 4:39 am

    müzikforum…

    müzik forum…

  • yabancı ünlüler says:
    2011-07-27 at 5:35 am

    Yerli ünlüler…

    yabancı ünlüler…

  • wedding bands says:
    2011-07-26 at 2:54 am

    diamonds and rings…

    wedding bands…

  • toptan mallar says:
    2011-07-25 at 5:26 am

    toptan mallar…

    toptan mallar…

  • Healh Care Videos says:
    2011-07-21 at 6:43 am

    Healh Care Videos…

    Finance Forex…

  • temizlik şirketleri says:
    2011-07-19 at 12:09 am

    temizlik şirketleri…

    temizlik şirketleri…

  • Alexander says:
    2011-07-7 at 10:46 am

    ……

    Need cheap generic VIAGRA?…

  • Manually remove Trojan-Clicker.Win32.Agent.dca says:
    2011-06-12 at 5:31 pm

    [...] View the original here: Manually remove trojan-Clicker.Win32.Agent.dca [...]

  • Leave a Reply:

    Click here to cancel reply.

    Name (required):
    Mail (will not be published) (required):
    Website:
    Comment (required):
    XHTML: You can use these tags: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>
    验证图片
    刷新验证码
    *

    Popular Articles

      • How to uninstall pc optimizer pro, pc optimizer pro removal 1139 comment(s)
      • what is Pbupdate.exe and how to fix Pbupdate.exe error? 1138 comment(s)

    latest comments

    • 正在加载...

    Tags

      Antivirus Suite Autorun ave.exe Backdoor Backdoor.Win32 Backdoor.Win32 removal browser home page was altered cc Clicker.dj Clunky Backdoor removal Default home page is modified DLL files error DOMDocument->load() downloader encountered Fix Kernel32 Dll Error MAC Microsoft Security Essentials PSW PSW.Kykymber.cc registry was modified remove MyWinLocker remove regedit32.exe remove safedrv.exe remove Trojan.Win32.Buzus.a Run command slow computer Speed Up Computer speed up pc Trojan Trojan-Downloader.Win32.Small.b removal Trojan-PSW.Win32 Trojan.Win32 Trojan.Win32 removal Trojan Downloader Trojan Dropper uninstall MyWinLocker variant dj Virus W32.Cervivec.A@mm Win32 Win32.Hack.GrayBird.al.761856 Win32.TrojDownloader.Guupk.ps Worm Worm.Win32

    Category

    • News
    • Others
    • Registry
    • Script
    • System Utility
    • Virus
    • Windows
    • XML

    Archives

    • December 2011
    • November 2011
    • October 2011
    • September 2011
    • July 2011
    • June 2011
    • May 2011
    • April 2011
    • March 2011
    • February 2011

    Links

    • Download Drivers

    Pages

    • Regtweaker
    • Spyware Cease
    
    Copyright © 2012 PC solutions. Powered by VersionHunter.com. registry repair |Threats Center
    Top