• Home
  • Regtweaker
  • Subscribe to Posts
  • Subscribe to comments

PC solutions

Give you Professional Suggestions

  • Home
  • News
  • Registry
  • Script
  • System Utility
  • Virus
  • Windows
  • XML
Home Virus Manually remove Trojan.Win32.Delux.am

Manually remove Trojan.Win32.Delux.am

Posted on Saturday, 21 May 2011
15 Comments
Share|

virus Name: trojan.Win32.Delux.am
Risk level: Medium

Virus Description

This virus is mainly through the “file bundle”, “download tool to download”, “web page linked to horse”, etc. to spread, the main purpose of the virus is to steal user’s computer information.

Infection in the operating system

Windows 2000/Windows XP / Windows 2003/Windows Vista / Windows 7

Transmission

Bundle file, web page linked to horse, download tools to download

Manual Solution:

1. Manually delete the following files
% SystemRoot% \ SYSTEM32 \ fwMonitor.exe
% SystemRoot% \ SYSTEM32 \ DRIVERS \ fwMonitor.sys

2. Manually delete the Registry
HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Services \ ZXSoft firewall control service

Variable declaration:

% SystemDriver% system where the partition, usually “C: \”
% SystemRoot% WINDODWS directory, usually “C: \ Windows”
% Documents and Settings% user file directory, usually “C: \ Documents and Settings”
% Temp% temp folder, usually “C: \ Documents and Settings \ current user name \ Local Settings \ Temp”
% ProgramFiles% system program the default installation directory, typically: “C: \ ProgramFiles”
Analysis of the Virus:

(1), find the present system have% SystemRoot% \ system32 \ fwMonitor.dlx, if not then create this file and write data.
(2), get the current virus process PID, create a process snapshot, traversal process, the process of matching the current virus PID, if the match is open the current process.
(3), compared with its own whether the% SystemRoot% \ SYSTEM32 \ fwMonitor.exe, if not, try to delete the% SystemRoot% \ SYSTEM32 \ fwMonitor.dll and% SystemRoot% \ SYSTEM32 \ ie.log, if these two files do not exist , create two files, and the release of the virus code into two files you just created, set the hidden attribute. Copy the virus itself was forced% SystemRoot% \ SYSTEM32 \ winload.dll and set the hidden attribute, move% SystemRoot% \ SYSTEM32 \ winload.dll to% SystemRoot% \ SYSTEM32 \ fwMonitor.exe, move% SystemRoot% \ SYSTEM32 \ ie.log to% SystemRoot% \ SYSTEM32 \ DRIVERS \.
(4), create a file called “ZXSoft firewall control service” of the service, start service, and create a corresponding service registry key HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Services \ ZXSoft firewall control service, to create successful delete itself, create a process running fwMonitor . exe.
(5), using Rootkit techniques to hide the virus process, virus source code, released from the dll component and virus-related information, and prevent detection and killing. After running the virus sending computer to the hacker a lot of information, leading to important personal privacy and information disclosure.

Virus to create files:

% SystemRoot% \ SYSTEM32 \ fwMonitor.exe
% SystemRoot% \ SYSTEM32 \ DRIVERS \ fwMonitor.sys

Virus to create the registry:

HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Services \ ZXSoft firewall control service
Name: Description Data: New Golden Shield firewall.
Name: DisplayName Data: ZXSoft firewall control service
Name: ImagePath Data:% SystemRoot% \ SYSTEM32 \ fwMonitor.exe-u


Share this Post:
Digg Google Bookmarks reddit Mixx StumbleUpon Technorati Yahoo! Buzz DesignFloat Delicious BlinkList Furl
Tagged with: Trojan.Win32 removal, Trojan.Win32.Delux.am removal

15 Responses to “Manually remove Trojan.Win32.Delux.am”

Trackbacks are disabled.

  • spor haberleri says:
    2011-08-15 at 4:17 am

    gol videoları…

    iddaa tahminleri…

  • superbahis giriş says:
    2011-08-14 at 8:26 am

    superbahis giriş…

    ukash…

  • ukash says:
    2011-08-14 at 5:06 am

    ukash…

    ukash kart…

  • borsa says:
    2011-08-9 at 6:55 am

    borsa…

    borsa haberleri…

  • metal çöp konteyner says:
    2011-08-6 at 6:37 am

    plastik çöp konteyneri…

    metal çöp konteyner…

  • polyester depo says:
    2011-08-2 at 4:41 am

    polyester depo…

    zeytin turşu deposu…

  • escort bayan says:
    2011-07-29 at 12:44 pm

    oo nice work…

    very ncy…

  • health videos says:
    2011-07-28 at 4:36 pm

    health videos…

    surgery videos…

  • film izle says:
    2011-07-28 at 5:40 am

    hd film izle…

    http://www.xfilm-izle.com/…

  • dis beyazlatma says:
    2011-07-28 at 3:47 am

    dis beyazlatma…

    dis kaplama…

  • Fiat picture says:
    2011-07-27 at 2:17 pm

    Fiat…

    Fiat picture…

  • eternity rings says:
    2011-07-26 at 5:45 am

    eternity rings…

    eternity rings…

  • toptan mallar says:
    2011-07-22 at 3:18 am

    toptan mallar…

    toptan mallar…

  • aspirinn says:
    2011-07-21 at 5:37 am

    aspirinn…

    hugebody…

  • Diablo 2 Items Store says:
    2011-05-23 at 6:16 am

    Diablo 2 Items…

    Hey, I like your thoughts but you should check out the design at my site(A Diablo 2 Items Selling Store) and let me know what you think! Diablo 2 Runes Here!…

  • Leave a Reply:

    Click here to cancel reply.

    Name (required):
    Mail (will not be published) (required):
    Website:
    Comment (required):
    XHTML: You can use these tags: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>
    验证图片
    刷新验证码
    *

    Popular Articles

      • How to uninstall pc optimizer pro, pc optimizer pro removal 1139 comment(s)
      • what is Pbupdate.exe and how to fix Pbupdate.exe error? 1138 comment(s)

    latest comments

    • 正在加载...

    Tags

      Antivirus Suite Autorun ave.exe Backdoor Backdoor.Win32 Backdoor.Win32 removal browser home page was altered cc Clicker.dj Clunky Backdoor removal Default home page is modified DLL files error DOMDocument->load() downloader encountered Fix Kernel32 Dll Error MAC Microsoft Security Essentials PSW PSW.Kykymber.cc registry was modified remove MyWinLocker remove regedit32.exe remove safedrv.exe remove Trojan.Win32.Buzus.a Run command slow computer Speed Up Computer speed up pc Trojan Trojan-Downloader.Win32.Small.b removal Trojan-PSW.Win32 Trojan.Win32 Trojan.Win32 removal Trojan Downloader Trojan Dropper uninstall MyWinLocker variant dj Virus W32.Cervivec.A@mm Win32 Win32.Hack.GrayBird.al.761856 Win32.TrojDownloader.Guupk.ps Worm Worm.Win32

    Category

    • News
    • Others
    • Registry
    • Script
    • System Utility
    • Virus
    • Windows
    • XML

    Archives

    • December 2011
    • November 2011
    • October 2011
    • September 2011
    • July 2011
    • June 2011
    • May 2011
    • April 2011
    • March 2011
    • February 2011

    Links

    • Download Drivers

    Pages

    • Regtweaker
    • Spyware Cease
    
    Copyright © 2012 PC solutions. Powered by VersionHunter.com. registry repair |Threats Center
    Top