• Home
  • Regtweaker
  • Subscribe to Posts
  • Subscribe to comments

PC solutions

Give you Professional Suggestions

  • Home
  • News
  • Registry
  • Script
  • System Utility
  • Virus
  • Windows
  • XML
Home Virus Manually remove Trojan-Downloader.Win32.Agent.bumi

Manually remove Trojan-Downloader.Win32.Agent.bumi

Posted on Monday, 6 June 2011
68 Comments
Share|

virus name: trojan-downloader.Win32.Agent.bumi

Risk level: Medium

Virus Description

The sample size is “49,252 bytes”, and its extension “. Exe”, mainly through the “file bundle”, “download tool to download”, “web page linked to horses” and other communication to spread the virus from the specified purpose download the virus to the user’s computer, the user’s computer after infected, will visit a large number of hacking sites specified, there system is running Slow, slow speed, a large number of unknown processes.

Infected OS

Windows 2000/Windows XP / Windows 2003/Windows Vista / Windows 7

Transmission

Bundle file, web page linked to horse, download tools to download

Manual Solution:

Manually delete the following files
% SystemRoot% \ system32 \ popupko.dll
% SystemRoot% \ system32 \ cehProcessgy.dll
% SystemDriver% \ wxclient

Variable declaration:

% SystemDriver% system where the partition, usually “C: \”
% SystemRoot% WINDODWS directory, usually “C: \ Windows”
% Documents and Settings% user file directory, usually “C: \ Documents and Settings”
% Temp% temp folder, usually “C: \ Documents and Settings \ current user name \ Local Settings \ Temp”
% ProgramFiles% system program the default installation directory, typically: “C: \ ProgramFiles”
Analysis of the virus:

(1) to determine whether its% SystemRoot% \ conime.exe, if not, copy itself to% SystemRoot% \ conime.exe, load the implementation of conime.exe, download http://www.011 **. com / 11d.txt to% SystemDriver% \ wxclient, get% SystemDriver% \ wxclient configuration content, configure content download according to a large number of unknown Trojans to run the machine.
(2), the release of the virus code into the% Temp% \ \ 332233404453.jpg (04453 random), modify the creation time and modification time. Copy 332233404453.jpg is% SystemRoot% \ system32 \ popupko.dll, set popupko.dll to hide property, remove 332233404453.jpg
(3), create% SystemDriver% \ supe0d3ef5s1x4a5d7f.bat batch file, write a batch command rundll32.exe popupko.dll FunctionStart, create a process to execute the batch loader run popupko.dll, delete% SystemDriver% \ supe0d3ef5s1x4a5d7f.bat .
(4), create a mutex cntest # 32770 prevent the virus from several runs, the process of creating a snapshot of the system, traverse to find cmd.exe, if there is forced to terminate the process.
(5), for cehProcessgy.dll configuration information, create threads, from time to time to open the specified website hacking, update configuration information.

Virus to create files

% Temp% \ \ 332233404453.jpg (04453 random)
% SystemDriver% \ wxclient
% SystemRoot% \ system32 \ popupko.dll
% SystemRoot% \ system32 \ cehProcessgy.dll

Virus to access the network:

http://www.011 **. com/5.exe
http://www .* mall.com /
http://u.589 **. com
http://www.suvvvs ***. com / d.php? type = 12 & said = 4349


Share this Post:
Digg Google Bookmarks reddit Mixx StumbleUpon Technorati Yahoo! Buzz DesignFloat Delicious BlinkList Furl
Tagged with: Trojan Downloader, Trojan-Downloader.Win32

68 Responses to “Manually remove Trojan-Downloader.Win32.Agent.bumi”

Trackbacks are disabled.

fred meyer extended warranty company
Learn to Kitesurf
car valuation by reg
duoderm cgf
Transparent film
Evil eye pendant
Evil eye store
Transparent film
Evil eye bracelets
Teeth Whitening Strips
AC Repair Fairfax VA
gynexin reviews
Mauritius Apartments
husqvarna 61 chainsaw parts
webuyanycar
Location Villas Ile Maurice
xenical
ps3 cheats save
Seattle property
Burberry Sunglasses
Appartements Ile Maurice
cover letters
acne natural
Location Ile Maurice
Online dating uk
Villa Ile Maurice
Villas Mauritius
Self Catering Accommodation Mauritius
Self Catering Accommodation Mauritius
Calorie diet menu
videochat
Sith Sorcerer Abilities Guide
landscaping designs
news entertainment
Pembrokeshire Carpet Cleaning
elder scrolls
betting tips
dao tao ke toan
the Best Workout Dvd
geovision camera
Investment News Today
UGG Classic Cardy Sale
transparent film
recipes for pork chop
female dominatrix movies online
Nollywood Gossip
investment property in melbourne
i need money
Ripstik Board
Lacoste Mens Arixia FD 2
investment property in melbourne
how to increase breast size
carchex auto warranty reviews extended auto warranties
Evil eye store
Evil eye bracelets
comprehensive auto insurance
  • Kite Boards says:
    2011-10-25 at 3:01 pm

    Kitesurf News…

    [...]the time to check out sites we have linked to underneath the[...]…

  • superbahis says:
    2011-08-14 at 6:33 am

    superbahis…

    superbahis giriş…

  • Fantastik film izle says:
    2011-08-11 at 6:51 am

    Dram filmi izle…

    Fantastik film izle…

  • salamura depo says:
    2011-08-5 at 7:11 am

    salamura depo…

    prefabrik konutlar…

  • çatılı konteyner says:
    2011-08-2 at 6:20 am

    çatılı konteyner…

    prefabrik…

  • tente sistemleri says:
    2011-07-30 at 4:10 am

    tente sistemleri…

    tente çeşitleri…

  • escort bayan says:
    2011-07-29 at 8:58 am

    oo nice work…

    very ncy…

  • hasta karyolası says:
    2011-07-28 at 3:00 am

    hasta karyolası…

    hasta karyolası…

  • Atatürk says:
    2011-07-27 at 12:35 pm

    Atatürk…

    Atatürk resimleri…

  • film izle says:
    2011-07-27 at 2:14 am

    film izle…

    dizi izle…

  • vets for pets says:
    2011-07-23 at 3:40 am

    vets for pets…

    pets for vets…

  • toptan mallar says:
    2011-07-22 at 3:07 am

    toptan mallar…

    toptan mallar…

  • Leave a Reply:

    Click here to cancel reply.

    Name (required):
    Mail (will not be published) (required):
    Website:
    Comment (required):
    XHTML: You can use these tags: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>
    验证图片
    刷新验证码
    *

    Popular Articles

      • How to uninstall pc optimizer pro, pc optimizer pro removal 1139 comment(s)
      • what is Pbupdate.exe and how to fix Pbupdate.exe error? 1138 comment(s)

    latest comments

    • 正在加载...

    Tags

      Antivirus Suite Autorun ave.exe Backdoor Backdoor.Win32 Backdoor.Win32 removal browser home page was altered cc Clicker.dj Clunky Backdoor removal Default home page is modified DLL files error DOMDocument->load() downloader encountered Fix Kernel32 Dll Error MAC Microsoft Security Essentials PSW PSW.Kykymber.cc registry was modified remove MyWinLocker remove regedit32.exe remove safedrv.exe remove Trojan.Win32.Buzus.a Run command slow computer Speed Up Computer speed up pc Trojan Trojan-Downloader.Win32.Small.b removal Trojan-PSW.Win32 Trojan.Win32 Trojan.Win32 removal Trojan Downloader Trojan Dropper uninstall MyWinLocker variant dj Virus W32.Cervivec.A@mm Win32 Win32.Hack.GrayBird.al.761856 Win32.TrojDownloader.Guupk.ps Worm Worm.Win32

    Category

    • News
    • Others
    • Registry
    • Script
    • System Utility
    • Virus
    • Windows
    • XML

    Archives

    • December 2011
    • November 2011
    • October 2011
    • September 2011
    • July 2011
    • June 2011
    • May 2011
    • April 2011
    • March 2011
    • February 2011

    Links

    • Download Drivers

    Pages

    • Regtweaker
    • Spyware Cease
    
    Copyright © 2012 PC solutions. Powered by VersionHunter.com. registry repair |Threats Center
    Top