trojan downloader: Trojan-Downloader.Win32.Agent.a
Risk level: Medium
virus Description
The sample is to use the “VC” prepared by the Trojan downloaders, the size of 37,260 bytes, the icon for the virus “
“, the extension “exe”, mainly through the “Web Trojan”, “file bundle”, “download tool download” modes to spread,
After the user’s computer was infected, the network will appear to run Slow, and unknown processes.
Infection of the operating system
Windows 2000/Windows XP / Windows 2003/Windows Vista / Windows 7
Transmission
Files binding, pages Trojan, download manager
Manual Solution:
1, manually delete the following files:
% SystemRoot% \ system32 \ WinHelp32.exe
2, delete to modify the Registry HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Services \ 360safe
Variable declaration:
% SystemDriver% partition where the operating system, typically “C: \”
% SystemRoot% WINDODWS directory, usually “C: \ Windows”
% Documents and Settings% user documentation directory, usually “C: \ Documents and Settings”
% Temp% temp folder, usually “C: \ Documents and Settings \ current user name \ Local Settings \ Temp”
% ProgramFiles% system program default installation directory, typically: “C: \ ProgramFiles”
Virus analysis:
1 after the execution of the sample, first check whether their path “% SystemRoot% \ system32 \ svchost.exe”. If the change in priority; create mutex “GNTWQ5TDNMXDGMZSGIXG64THHI4DAMBQ”; create threads for the operating system version information, sent to the specified URL. And modify the registry HKEY_LOCAL_MACHINE \ HARDWARE \ DESCRIPTION \ System \ CentralProcessor \ 0 ProcessorNameString
2 If not, check again whether the “% SystemRoot% \ system32 \ WinHelp32.exe”. If the failure classifies himself replaced WinHelp32.exe.
Call CreateProcessInternalA execute this file. Call the command to delete itself.
3 If WinHelp32.exe, create named 360safe service, start the service.
And create the registry key HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Services \ 360safe item name Description.
The virus creates a file:
% SystemRoot% \ system32 \ WinHelp32.exe
Virus delete the file:
% SystemRoot% \ system32 \ WinHelp32.exe
Woah this blog is excellent i like reading your posts. Keep up the good paintings! You already know, many persons are looking around for this info, you could aid them greatly.
Howdy very cool blog!! Guy .. Beautiful .. Superb .. I’ll bookmark your blog and take the feeds additionally?I’m satisfied to seek out so many useful information here in the submit, we’d like develop more techniques on this regard, thanks for sharing. . . . . .
Just desire to say your article is as astonishing. The clearness on your publish is simply nice and that i can think you’re an expert on this subject. Fine with your permission let me to grasp your RSS feed to keep updated with coming near near post. Thanks a million and please carry on the gratifying work.
I liked as much as you will receive carried out right here. The cartoon is attractive, your authored material stylish. nonetheless, you command get bought an nervousness over that you want be delivering the following. unwell indisputably come more previously again as precisely the same just about a lot regularly inside of case you defend this hike.
Pretty insightful post, I personally was in fact truly satisfied to locate your site over the internet. I put a weblink on my personal blog page and so my visitors may perhaps access your website or blog. Don’t hesitate to take a glimpse.
vintage dolls…
Would you be interested in exchanging hyperlinks?…
Could have been better…
Excellent thought although it is not on everyone’s mind like Sharpay Evans or is it?…
Lost, Again…
I haven’t any idea about this blog post. None of it made sense to me….
Fender Guitars…
The subsequent time I read a weblog, I hope that it doesnt disappoint me as much as this one. I mean, I know it was my option to read, but I actually thought youd have some thing fascinating to say. All I hear is a bunch of whining about something that…
Antique Clocks…
Spot on with this write-up, I truly believe this website needs much more consideration. I’ll most likely be once more to read much more, many thanks for that info….
Mantel Clocks…
I’d have to verify with you here. Which isn’t some thing I generally do! I appreciate studying a publish that will make individuals think. Also, thanks for allowing me to remark!…
british cars…
Your place is valueble for me. Many thanks!…