trojan downloader: Trojan.Win32.Buzus.a
Acquisition time :2010-5-23
Hazard rating: High
virus symptoms
The sample is a Trojan downloader which was developed by “Delphi”. Use “FSG” packers way, after the size of packers, “59,349″ bytes, the icon for the virus “
“, the extension “exe”, mainly through the “Web Trojan”, “file bundle”, “download manager” “removable storage media” and to spread. The main purpose of the virus is to download and install Trojan virus, steal game account password.
After the user’s computer was infected, there appears anomalous network security software for no reason out of the system error or crash for no reason and found a large number of unknown process, the game account password theft (such as World of Warcraft) and so on.
Infected objects
Windows 2000/Windows XP / Windows 2003/Windows Vista / Windows 7
Transmission
Removable storage media, Web Trojans, file bundle, download manager
Manual Solution:
1. Manually delete the following files:
% Program Files% \ Common Files \ safedrv.exe
% Documents and Settings% \ Administrator \ ttexn.drv
% Documents and Settings% \ Administrator \ eqjvu.drv
X: \ aurorun.inf (X is the letter of the infected disk)
X: \ SafeDrv.exe
2. Manually delete the following Registry:
HKEY_LOCAL_MACHINE \ SYSTEM \ ControlSet001 \ Services \ SharedAccess \ Parameters \ FirewallPolicy \ StandardProfile \ AuthorizedApplications \ List
Data: C: \ Program Files \ Common Files \ SafeDrv.exe
Value: C: \ Program Files \ Common Files \ SafeDrv.exe: *: Enabled: @ xpsp2res.dll, -22019
HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ policies \ Explorer \ Run
Data: SafeDrv
Value: C: \ Program Files \ Common Files \ SafeDrv.exe
3. Delete registry HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows NT \ CurrentVersion \ Image File Execution Options item under the security software hijacking.
4.Went to the same system of C: \ WINDOWS \ system32 \ srsvc.dll file, use the system files ysrsvc.dll to replace it.
Also to turn off or remove the following driver
Driver program:
[Fusnfc / fusnfc] [Running / Manual Start]
<\?? \ C: \ DOCUME ~ 1 \ ADMINI ~ 1 \ LOCALS ~ 1 \ Temp \ ~ fusnfc.txt> <N/A> system
Variable declaration:
% SystemDriver% partition where the operating system, typically “C: \”
% SystemRoot% WINDODWS directory, usually “C: \ Windows”
% Documents and Settings% user documentation directory, usually “C: \ Documents and Settings”
% Temp% temp folder, usually “C: \ Documents and Settings \ current user name \ Local Settings \ Temp”
% ProgramFiles% system program default installation directory, typically: “C: \ ProgramFiles”
The virus creates a file:
% Program Files% \ Common Files \ SafeDrv.exe
% Documents and Settings% \ Administrator \ ttexn.drv (random filename)
% Documents and Settings% \ Administrator \ eqjvu.drv
X: \ aurorun.inf (X is the letter of the infected disk)
X: \ SafeDrv.exe
Virus to create the registry:
HKEY_LOCAL_MACHINE \ SYSTEM \ ControlSet001 \ Services \ SharedAccess \ Parameters \ FirewallPolicy \ StandardProfile \ AuthorizedApplications \ List
Data: C: \ Program Files \ Common Files \ SafeDrv.exe
Value: C: \ Program Files \ Common Files \ SafeDrv.exe: *: Enabled: @ xpsp2res.dll, -22019
HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ policies \ Explorer \ Run
Data: SafeDrv
Value: C: \ Program Files \ Common Files \ SafeDrv.exe
Virus access to the network:
http://x.2012 *** n.com: 82/wow.exe
http://x.2012 *** n.com: 82/tl.exe
http://x.2012 *** n.com: 82/wd.exe
http://x.2012 *** n.com: 82/jx3.exe
http://x.2012 *** n.com: 82/dh2.exe
http://x.2012 *** n.com: 82/mz.exe
http://x.2012 *** n.com: 82/wm.exe
http://x.2012 *** n.com: 82/qqhx.exe
http://x.2012 *** n.com: 82/cq.exe
http://x.2012 *** n.com: 82/cs.exe
http://x.2012 *** n.com: 82/lszt.exe
http://x.2012 *** n.com: 82/jx.exe
http://x.2012 *** n.com: 82/qqsg.exe
http://x.2012 *** n.com: 82/sgcq.exe
http://x.2012 *** n.com: 82/zx2.exe
http://x.2012 *** n.com: 82/jx3.exe
http://x.2012 *** n.com: 82/zt.exe
http://x.2012 *** n.com: 82/dnf.exe
http://x.2012 *** n.com: 82/qq.exe
http://x.2012 *** n.com: 82/fhie.exe
I will right away grab your rss as I can’t find your email subscription link or e-newsletter service. Do you have any? Kindly let me know so that I may subscribe. Thanks.
I cherished up to you will obtain carried out proper here. The comic strip is attractive, your authored material stylish. however, you command get bought an nervousness over that you wish be handing over the following. sick indubitably come further earlier again as exactly the same nearly very incessantly inside case you shield this increase.
That’s the best awnesr of all time! JMHO
Really insightful blog, I actually was indeed grateful to seek out your website or blog on the net. I put a link upon my blog for that reason my readers could possibly get through to a site. Please take a glimpse.
Hello…..
Thank you for sharing superb informations. Your website is very cool. I’m impressed by the details that you have on this blog. It reveals how nicely you understand this subject. Bookmarked this website page, will come back for extra articles. You, my …
Another Title…
I saw this really great post today….
Hey……
I have recently started a site, the info you offer on this web site has helped me tremendously. Thanks for all of your time & work. “You do ill if you praise, but worse if you censure, what you do not understand.” by Leonardo DaVinci….
Informative and precise…
Its difficult to find informative and precise information but here I found…
liberty reserve I got what you intend, thanks for up. Woh I am glad to gain this website google….
I got what you intend, thanks for up. Woh I am glad to gain this website google….
Wikia…
Wika linked to this website…