Trojans: trojan.Win32.Generic.mrw
Risk level: Medium
virus Description
The virus is a Flash memory virus which is compiled using the GCC C-programming, size is 21,054 bytes, the icon is “
“, viruses extension “exe”, mainly through the “file bundle”, ” Flash memory disk Autorun”, etc. to spread. The main purpose of the virus is to destroy some features of a computer and infected the user’s flash drive
After the user’s computer was infected, there will be computer and network running Slow, can not open task manager, flash drive auto run programs and other features.
Infection in the operating system
Windows 2000/Windows XP / Windows 2003/Windows Vista / Windows 7
Transmission
Bundle file, web page linked to horse, download software download
Manually removal:
1, manually delete the following files:
% SystemRoot% \ system32 \ windowshelp.exe
U disk directory: \ driverusb.exe
U disk directory: \ autorun.inf
2, manually delete the following Registry:
HKEY-LOCAL-MACHINE \ Software \ Microsoft \ Windows \ CurrentVersion \ Run
Name: Windows Help
Data:% SystemRoot% \ system32 \ windowshelp.exe
3, turn off Windows automatic playback function
Variable declaration:
% SystemDriver% system where the partition, usually “C: \”
% SystemRoot% WINDODWS directory, usually “C: \ Windows”
% Documents and Settings% user’s documents directory, usually “C: \ Documents and Settings”
% Temp% temp folder, usually “C: \ Documents and Settings \ current user name \ Local Settings \ Temp”
% ProgramFiles% system program default installation directory, typically: “C: \ ProgramFiles”
Virus
1, find the system directory at first % SystemRoot% \ system32 procedures under the Task Manager taskmgr.exe, there is delete the file, disable windows task manager;
2 copies itself to % SystemRoot% \ system32 directory, and rename it to windowshelp.exe, setting the property to read-only, system, hidden;
3, modify the registry startup items, so windowshelp.exe file and boot from boot;
4, through all removable storage devices, will find the virus copies itself to all flash drive directory, and rename it to dirverusb.exe, set file attributes to read-only, system, hidden;
5, create autorun.inf to all flash drive directory, targeting dirverusb.exe, so dirverusb.exe with flash drive automatically, and set their own property is read-only, system, hidden;
6, when mount the flash drive into the computer, the virus uses the windows AutoPlay feature to achieve self-starting, running infected computers and other removable disks;
Virus to create the following files:
% SystemRoot% \ system32 \ windowshelp.exe
U disk directory: \ driverusb.exe
U disk directory: \ autorun.inf
Virus delete file:
% SystemRoot% \ system32 \ taskmgr.exe
Virus to create the registry:
HKEY-LOCAL-MACHINE \ Software \ Microsoft \ Windows \ CurrentVersion \ Run
Name: Windows Help
Data:% SystemRoot% \ system32 \ windowshelp.exe
Thanks for the good writeup. It in fact was a leisure account it. Glance advanced to more brought agreeable from you! However, how can we keep in touch?
Pretty component to content. I simply stumbled upon your blog and in accession capital to claim that I get in fact loved account your blog posts. Anyway I’ll be subscribing to your augment and even I success you access consistently quickly.
Hi, just that without a doubt if you want any sites to beat your competition you’ll need a tricky link building strategy! When I need quick results I just visit http://juicylinks.netii.net/ and they will not fail! Without question I see a boost in sales and their strategy is rock solid! But if you have the proper tools it is something you could do yourself! Message me if you wanna know what tools!!
ykiWxj , [url=http://fogpawzkhvpb.com/]fogpawzkhvpb[/url], [link=http://bfhkubvkcypi.com/]bfhkubvkcypi[/link], http://phfvymxkyzmh.com/
UXETN2 , [url=http://naxsleoggkjz.com/]naxsleoggkjz[/url], [link=http://kpovyipdbxsj.com/]kpovyipdbxsj[/link], http://czybjuqqfnjq.com/
Retiro lo dicho este1 buena y deja un mensaje poisvito.Es cierto lo que muestra: las oportunidades se van y ya no vuelven a ser iguales,pero vienen otra vez y de otra forma para que alcancemos la meta para la que estuvimos hechos.Es obra de Dios,del destino,del karma,de la causa-efecto o como quieran llamarle.Como dijo Steve Jobs en Harvard tenemos que CERRAR CcdRCULOS en la vida y para eso es necesario DECIDIR CREER.
Wonderful publish, very informative. I’m wondering why the opposite specialists of this sector do not understand this. You must continue your writing. I’m confident, you’ve a great readers’ base already!|What’s Taking place i am new to this, I stumbled upon this I have found It positively helpful and it has helped me out loads. I am hoping to contribute & assist different customers like its helped me. Good job.
of course like your web site however you need to test the spelling on several of your posts. A number of them are rife with spelling problems and I find it very troublesome to inform the truth however I will surely come again again.
Great post.Thanks for sharing such a useful information with us.
That is really attention-grabbing, You’re a very skilled blogger. I’ve joined your feed and look forward to searching for extra of your wonderful post. Also, I’ve shared your website in my social networks
Very insightful post, I personally was glad to locate your websites on the web. I put a link in my own web site hence my followers may reach web site. Please take a glimpse.
Brainsucker article…
There went 39 IQ points, gone by reading this news item….
Mortgage Calculators…
[...]Here is an excellent Weblog You may Uncover Exciting that we Encourage You[...]…
Its hard to find good help…
I am constantnly saying that its difficult to get quality help, but here is…
Recent Blogroll Additions……
[...]usually posts some very interesting stuff like this. If you’re new to this site[...]……
Sources…
[...]check below, are some totally unrelated websites to ours, however, they are most trustworthy sources that we use[...]……