• Home
  • Regtweaker
  • Subscribe to Posts
  • Subscribe to comments

PC solutions

Give you Professional Suggestions

  • Home
  • News
  • Registry
  • Script
  • System Utility
  • Virus
  • Windows
  • XML
Home Virus Manually remove Trojan-PSW.Win32.Element.hu

Manually remove Trojan-PSW.Win32.Element.hu

Posted on Tuesday, 24 May 2011
13 Comments
Share|

virus Name: trojan-PSW.Win32.Element.hu

Risk level: Medium

Virus Description
This virus sample extension “. Exe”, virus is mainly through the “file bundle”, “download tool to download”, “web page linked to horse”, etc. to spread, the main purpose of the virus is to steal user’s game account, the user’s computer after infected, virus replace the dll file of operating system directory , resulting in operating system to run slowly, found unknown process.

Infection in the operating system

Windows 2000/Windows XP / Windows 2003/Windows Vista / Windows 7

Transmission

Bundle file, web page linked to horse, download tools to download

Manual Solution:

1, manually delete the following files

% SystemRoot% \ system32 \ 1008.ocx
% SystemRoot% \ system32 \ elementclientwl01.ocx

2, replace the following three files as normal files

% SystemRoot% \ system32 \ dsound.dll
% SystemRoot% \ system32 \ ddraw.dll
% SystemRoot% \ system32 \ comres.dll

Variable declaration:

% SystemDriver% system where the partition, usually “C: \”
% SystemRoot% WINDODWS directory, usually “C: \ Windows”
% Documents and Settings% user file directory, usually “C: \ Documents and Settings”
% Temp% temp folder, usually “C: \ Documents and Settings \ current user name \ Local Settings \ Temp”
% ProgramFiles% system program the default installation directory, typically: “C: \ ProgramFiles”

Analysis of the virus:

(1), enumerate all top-level window on the screen to find whether there is called “Element Client” window of the process, if there is to terminate the process.
(2), try to move the% SystemRoot% \ system32 \ 1008.ocx to temp, if the file does not exist, create% SystemRoot% \ system32 \ 1008.ocx and% SystemRoot% \ system32 \ elementclientwl01.ocx, created after the success of the release of virus source code to the newly created two files, and then set it as hidden attributes.
(3), create% SystemRoot% \ system32 \ system.ini configuration files and write configuration information. Copy% SystemRoot% \ system32 \ dsound.dll is% SystemRoot% \ system32 \ New.dll. Get dsound.dll PE header and the section information to the buffer, modify the% SystemRoot% \ system32 \ New.dll PE header, add a data2 section, access to% SystemRoot% \ system32 \ dsound.dll file creation time and modification time, set the% SystemRoot% \ system32 \ New.dll the creation time and modification time for the newly acquired time. Function call sfc_os.dll 5 , lifting windows system file protection, backup% SystemRoot% \ system32 \ dsound.dll, and then copy the% SystemRoot% \ system32 \ New.dll to% SystemRoot% \ system32 \ dsound.dll, so as to achieve replacement The purpose of the system components of the normal dsound.dll.
(4), backup% SystemRoot% \ system32 \ ddraw.dll and% SystemRoot% \ system32 \ comres.dll, copy the two% SystemRoot% \ system32 \ New.dll was% SystemRoot% \ system32 \ ddraw.dll and% SystemRoot% \ system32 \ comres.dll, and ddraw.dll and comres.dll PE add malicious code to reorganize the structure, restore the original ddraw.dll and comres.dll file creation time and modification time.
(5), the current directory in the new batch file virus, called WinExec execute this file delete itself.
(6), when start the game automatically loads% SystemRoot% \ system32 \ dsound.dll,% SystemRoot% \ system32 \ ddraw.dll and% SystemRoot% \ system32 \ comres.dll, virus program to create a keyboard hook, memory interception of Pirates games take the user account.

Virus to create a file:

% SystemRoot% \ system32 \ 1008.ocx
% SystemRoot% \ system32 \ elementclientwl01.ocx

Replace the following three systems the normal virus files:

% SystemRoot% \ system32 \ dsound.dll
% SystemRoot% \ system32 \ ddraw.dll
% SystemRoot% \ system32 \ comres.dll

Virus delete files:

% SystemRoot% \ system32 \ dsound.dll
% SystemRoot% \ system32 \ ddraw.dll
% SystemRoot% \ system32 \ comres.dll


Share this Post:
Digg Google Bookmarks reddit Mixx StumbleUpon Technorati Yahoo! Buzz DesignFloat Delicious BlinkList Furl
Tagged with: Trojan-PSW.Win32, Trojan-PSW.Win32.Element.hu removal

13 Responses to “Manually remove Trojan-PSW.Win32.Element.hu”

Trackbacks are disabled.

  • kredi karti borcu taksitlendirme says:
    2011-10-15 at 12:03 pm

    kredi karti borcu taksitlendirme…

    this was a sheer entertaining read. i enjoyed it very much!|Thanks for this article! How in the world….

  • maç dinle says:
    2011-08-31 at 10:09 pm

    canlı maç izle…

    iddaa tahminleri…

  • iddaa tahminleri says:
    2011-08-15 at 7:00 am

    online maç izle…

    iddaa tahminleri…

  • superbahis giriş says:
    2011-08-14 at 8:29 am

    ukash…

    ukash kart…

  • ukash says:
    2011-08-14 at 4:53 am

    ukash kart…

    ukash…

  • Aksiyon filmi izle says:
    2011-08-11 at 6:31 am

    Aksiyon filmi izle…

    Macera filmi izle…

  • borsa says:
    2011-08-9 at 4:53 am

    borsa…

    borsa haberleri…

  • prefabrik says:
    2011-08-2 at 2:15 am

    prefabrik…

    iki katlı prefabrik ev…

  • raylı tente says:
    2011-07-30 at 5:28 am

    raylı tente…

    tenteci…

  • escort bayan says:
    2011-07-29 at 7:19 am

    oo nice work…

    very ncy…

  • ebru şallı plates says:
    2011-07-28 at 3:42 pm

    ebru şallı plates izle…

    ebru şallı plates…

  • toptan mallar says:
    2011-07-22 at 2:55 am

    toptan mallar…

    toptan mallar…

  • Healh Care Videos says:
    2011-07-21 at 6:49 am

    Healh Care Videos…

    Finance Forex…

  • Leave a Reply:

    Click here to cancel reply.

    Name (required):
    Mail (will not be published) (required):
    Website:
    Comment (required):
    XHTML: You can use these tags: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>
    验证图片
    刷新验证码
    *

    Popular Articles

      • How to uninstall pc optimizer pro, pc optimizer pro removal 1139 comment(s)
      • what is Pbupdate.exe and how to fix Pbupdate.exe error? 1138 comment(s)

    latest comments

    • 正在加载...

    Tags

      Antivirus Suite Autorun ave.exe Backdoor Backdoor.Win32 Backdoor.Win32 removal browser home page was altered cc Clicker.dj Clunky Backdoor removal Default home page is modified DLL files error DOMDocument->load() downloader encountered Fix Kernel32 Dll Error MAC Microsoft Security Essentials PSW PSW.Kykymber.cc registry was modified remove MyWinLocker remove regedit32.exe remove safedrv.exe remove Trojan.Win32.Buzus.a Run command slow computer Speed Up Computer speed up pc Trojan Trojan-Downloader.Win32.Small.b removal Trojan-PSW.Win32 Trojan.Win32 Trojan.Win32 removal Trojan Downloader Trojan Dropper uninstall MyWinLocker variant dj Virus W32.Cervivec.A@mm Win32 Win32.Hack.GrayBird.al.761856 Win32.TrojDownloader.Guupk.ps Worm Worm.Win32

    Category

    • News
    • Others
    • Registry
    • Script
    • System Utility
    • Virus
    • Windows
    • XML

    Archives

    • December 2011
    • November 2011
    • October 2011
    • September 2011
    • July 2011
    • June 2011
    • May 2011
    • April 2011
    • March 2011
    • February 2011

    Links

    • Download Drivers

    Pages

    • Regtweaker
    • Spyware Cease
    
    Copyright © 2012 PC solutions. Powered by VersionHunter.com. registry repair |Threats Center
    Top