• Home
  • Regtweaker
  • Subscribe to Posts
  • Subscribe to comments

PC solutions

Give you Professional Suggestions

  • Home
  • News
  • Registry
  • Script
  • System Utility
  • Virus
  • Windows
  • XML
Home Virus Manually remove Trojan.Win32.Sasfis.a

Manually remove Trojan.Win32.Sasfis.a

Posted on Monday, 28 March 2011
17 Comments
Share|

backdoor: trojan.Win32.Sasfis.a

Risk level: Medium

virus Description
The sample is a Worm program that uses “Delphi” prepared, it is used “UPX” packers way, packers after the size of “57,344″ bytes, the icon is “remove Backdoor Trojan“, it use of “exe” extension, through the file bundle, web hanging horse, download tools to download or the other way to spread. Virus main purpose is to control the user’s computer.
The user’s computer system is running occurs slowly after infected, open the camera for no reason, personal data leakage, and so on.

Infection in the operating system

Windows 2000/Windows XP / Windows 2003/Windows Vista / Windows 7

Transmission

Web page linked to horse, file bundle, download tools to download

Manual Solution:

1. Manually delete the following files

% ProgramFiles% \ DBS.EXE

2. Delete the following Registry

HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Services \ DBS_Server

Variable declaration:

% SystemDriver% system where the partition, usually “C: \”
% SystemRoot% WINDODWS directory, usually “C: \ Windows”
% Documents and Settings% user file directory, usually “C: \ Documents and Settings”
% Temp% temp folder, usually “C: \ Documents and Settings \ current user name \ Local Settings \ Temp”
% ProgramFiles% system program the default installation directory, typically: “C: \ ProgramFiles”

Analysis of the virus:

1. Create mutex to prevent multiple runs. Check whether their own% ProgramFiles% \ DBS.EXE, or% SystemRoot% \ SYSTEM32 \ userinit.exe
2. If not it will copy itself to% ProgramFiles% \ DBS.EXE, and to establish the CLSID in the registry value. And load the operating DBS.exe.
3. If the self is DBS.exe, userinit.exe process is hidden and will start the system itself is written to the userinit.exe process space and run into the system process. Change the registry to achieve self-starting.
4. If you own the userinit.exe is waiting for network connection, try to establish a connection with the remote host to listen to the command, the local machine completely under the control of hackers.

Virus to create a file:

% ProgramFiles% \ DBS.EXE

Virus to create the registry:

HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Services \ DBS_Server

Virus to access the network:

chb132520.3322.org


Share this Post:
Digg Google Bookmarks reddit Mixx StumbleUpon Technorati Yahoo! Buzz DesignFloat Delicious BlinkList Furl
Tagged with: remove Trojan.Win32.Sasfis.a, Trojan.Win32.Sasfis.a removal

17 Responses to “Manually remove Trojan.Win32.Sasfis.a”

Trackbacks are disabled.

svenskt missbruk
guld köpa ädelmetaller
fakta shanghai
länkar om psykologi
tolvstegsprogrammet behandling
  • fungerar roaccutan mot finnar says:
    2011-10-2 at 2:36 am

    fungerar roaccutan mot finnar…

    [...]k I own a similar site to this one and I was just curious if you get a lot of 8i[...]…

  • bra kattmat says:
    2011-10-1 at 1:18 am

    bra kattmat…

    [...]u I own a similar website to this one and I was just curious if you get a lot cs[...]…

  • Triumfbågen okända soldatens grav says:
    2011-10-1 at 12:28 am

    Triumfbågen okända soldatens grav…

    [...]c Hmmm that was weird, my comment seems to have been eaten. Anyway I wanted t tp[...]…

  • travel promo coupons says:
    2011-09-29 at 8:15 pm

    travel promo coupons…

    [...]5 This is is great. You’re a very professional blogger. I’ve joined your er[...]…

  • Basilikan Sacre Coeur says:
    2011-09-29 at 11:37 am

    Basilikan Sacre Coeur…

    [...]n I am visiting this land for the first time. I have come to know a lot of in 2v[...]…

  • stockholm gymnasium says:
    2011-09-29 at 7:05 am

    stockholm gymnasium…

    [...]k Just added this blog to my favorites. I enjoy reading your websites and hop us[...]…

  • shanghai historik år says:
    2011-09-29 at 3:50 am

    shanghai historik år…

    [...]6 I own a similar blog to this one and I was just curious if you get a lot of dw[...]…

  • eurodisney says:
    2011-09-29 at 12:41 am

    eurodisney…

    [...]w Hmmm that was weird, my comment seems to have been eaten. Anyway I wanted t ey[...]…

  • barmästare utbildning says:
    2011-09-28 at 3:23 pm

    barmästare utbildning…

    [...]y Very few websites that happen to be detailed below, from our point of view qc[...]…

  • perfekt konkurrens says:
    2011-09-28 at 1:33 pm

    perfekt konkurrens…

    [...]o Hmmm that was weird, my comment seems to have been eaten. Anyway I wanted t re[...]…

  • Victoria peak utsikt says:
    2011-09-28 at 4:58 am

    Victoria peak utsikt…

    [...]u I own a similar blog to this one and I was just curious if you get a lot of ec[...]…

  • Gertie Whistler says:
    2011-09-10 at 3:13 pm

    bill aboves…

    yea nice Work. Hello, sry for my bad english but Ih ave observed your web page and would say that I locate your posts great since they have give me new suggestions and new aspects. Many thanks for this details. terrific outstanding more please….

  • Leave a Reply:

    Click here to cancel reply.

    Name (required):
    Mail (will not be published) (required):
    Website:
    Comment (required):
    XHTML: You can use these tags: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>
    验证图片
    刷新验证码
    *

    Popular Articles

      • How to uninstall pc optimizer pro, pc optimizer pro removal 1139 comment(s)
      • what is Pbupdate.exe and how to fix Pbupdate.exe error? 1138 comment(s)

    latest comments

    • 正在加载...

    Tags

      Antivirus Suite Autorun ave.exe Backdoor Backdoor.Win32 Backdoor.Win32 removal browser home page was altered cc Clicker.dj Clunky Backdoor removal Default home page is modified DLL files error DOMDocument->load() downloader encountered Fix Kernel32 Dll Error MAC Microsoft Security Essentials PSW PSW.Kykymber.cc registry was modified remove MyWinLocker remove regedit32.exe remove safedrv.exe remove Trojan.Win32.Buzus.a Run command slow computer Speed Up Computer speed up pc Trojan Trojan-Downloader.Win32.Small.b removal Trojan-PSW.Win32 Trojan.Win32 Trojan.Win32 removal Trojan Downloader Trojan Dropper uninstall MyWinLocker variant dj Virus W32.Cervivec.A@mm Win32 Win32.Hack.GrayBird.al.761856 Win32.TrojDownloader.Guupk.ps Worm Worm.Win32

    Category

    • News
    • Others
    • Registry
    • Script
    • System Utility
    • Virus
    • Windows
    • XML

    Archives

    • December 2011
    • November 2011
    • October 2011
    • September 2011
    • July 2011
    • June 2011
    • May 2011
    • April 2011
    • March 2011
    • February 2011

    Links

    • Download Drivers

    Pages

    • Regtweaker
    • Spyware Cease
    
    Copyright © 2012 PC solutions. Powered by VersionHunter.com. registry repair |Threats Center
    Top