• Home
  • Regtweaker
  • Subscribe to Posts
  • Subscribe to comments

PC solutions

Give you Professional Suggestions

  • Home
  • News
  • Registry
  • Script
  • System Utility
  • Virus
  • Windows
  • XML
Home Virus Manually remove Worm Worm.Win32.Agent.vvp

Manually remove Worm Worm.Win32.Agent.vvp

Posted on Monday, 25 April 2011
348 Comments
Share|

Worm Worm.Win32.Agent.vvp

Risk level: Medium

virus Description

The sample is to use the “C / C” prepared by the worm process, the use of “UPX” packers approach attempts to evade signature scanning, the size of after packed “25,600″ bytes, the icon for the virus “Worm.Win32.Agent.vvp“, extension “exe” , mainly through the “file bundle”, “download tools to download ” “page linked to horse”, etc., the viruses main purpose is to spread itself using a removable disk, download the virus to the local computer.
After the user’s computer was infected, the system will appear to run Slow, there are a large number of known suspicious processes, systems and so important information is lost.

Infection in the operating system

Windows 2000/Windows XP / Windows 2003/Windows Vista / Windows 7

Transmission

Bundle file, web page linked to horse, download tools to download

Manual Solution:

1. Stop and delete the display name “ScsiDrv” system service items.
2. Manually delete the following Registry key:
HKLM \ System \ CurrentControlSet \ Services \ ScsiDrv
Name: Imagepath
Data: C: \ Windows \ system32 \ drivers \ scsi4dos.sys
3. Clear the temporary folder of the machine.
4. If the removable disk has been infected, delete the root directory of the disk \ … \ RECYCLER, autorun.inf

Variable declaration:

% SystemDriver% system where the partition, usually “C: \”
% SystemRoot% WINDODWS directory, usually “C: \ Windows”
% Documents and Settings% user file directory, usually “C: \ Documents and Settings”
% Temp% temp folder, usually “C: \ Documents and Settings \ current user name \ Local Settings \ Temp”
% ProgramFiles% system program the default installation directory, typically: “C: \ ProgramFiles”
Virus

1. The sample is running, running to get their own path, to determine whether their own “C: \ WINDOWS \ system32 \ drivers \ scsi4dos.sys”.
2. If not then copies itself to “% SystemRoot% \ system32 \ drivers” folder and renamed “scsi4dos.sys”.
3. Try to open called “ScsiDrv” of system services, if the open fails, then create a show called “ScsiDrv”, type SERVICE_AUTO_START system services, point to “C: \ WINDOWS \ system32 \ drivers \ scsi4dos.sys”, to achieve The boot virus, corresponding to the following registry key:
HKLM \ System \ CurrentControlSet \ Services \ ScsiDrv
Name: Imagepath
Data: C: \ Windows \ system32 \ drivers \ scsi4dos.sys
4. Create a process to run “scsi4dos.sys” and exit.
5.scsi4dos.sys running, create a process to run the system file svchost.exe and unload its memory image, and then injected into the process their own files to execute, and delete their own source file.
6. Created called “EvilEva” mutex object, to prevent repeat run.
7. Create a thread, the thread after the test whether the implementation of networking, then sleep for 60 seconds if no network re-test.
8. If it is found it will connect the local network hackers to specify a URL, download the virus to the local temporary file and run it.
9. Traversal local disk, if found “DRIVE_REMOVABLE” type of disk in the disk root directory create a directory “x: \ \ … \”, to copy itself to the directory, renamed the “RECYCLER”, and Create a file under the root directory “autorun.inf” file pointing to the virus file, to use a removable disk spread their own purposes.

Virus to create a file:

% SystemRoot% \ System32 \ Drivers \ scsi4dos.sys
x: \ autorun.inf
x: \ \ … \ RECYCLER (x for the infected removable disk drive letter)

Virus delete files:

% SystemRoot% \ system32 \ drivers \ scsi4dos.sys

Virus modifies the registry:

HKLM \ System \ CurrentControlSet \ Services \ ScsiDrv
Name: Imagepath
Data: C: \ Windows \ system32 \ drivers \ scsi4dos.sys

Virus to access the network:

http://hi .*** du.com


Share this Post:
Digg Google Bookmarks reddit Mixx StumbleUpon Technorati Yahoo! Buzz DesignFloat Delicious BlinkList Furl
Tagged with: Worm.Win32.Agent.vvp removal

348 Responses to “Manually remove Worm Worm.Win32.Agent.vvp”

Trackbacks are disabled.

metformin side effects
Devisenhandel
Roava Klvkaa
HQ Hydra Sale
coron hilltop view
my weblog
Cheap iPhone 4S
paintings
Tejados.biz
My Blog Title
4x4
4x4 sale
triathlon wetsuits
ourdoor inflatables
how a company goes public
second hand cars
IPO steps
penny stock tips
electrician directory
Location Villa Ile Maurice
used car valuation
car valuation
siker
safari lodges
franchise opportunities
curtain poles
Download Islamic Softwares
Cosmetic Dentist Woodland Hills
Medical equipment
Look at this
Schwinn 240
seo services
Med supplies
Mauritius Villa Rental
Apartments in Mauritius
Cheap Rain Boots
Bird House Feeder
high quality low size movies
Evil eye pendant
Air Compressor
My Blog Title
Mauritius Holiday Villas
car valuation by reg
Evil eye pendant
Foundation Financial Group
Scott Tucker
Location Vacances Ile Maurice
check this out
Scott Tucker
csajozás
Sprinkler System Fairfax VA
how to get rid of gynecomastia
top weight loss supplements
Acne No More Review
cheap matresses uk
Mauritius Accommodation
making money online
Ripley Hampers
british shorthair kittens for sale
Discount Beauty Products
Migraine Medications
halifax electrical contractors
Alliance leveling guide review
best Halloween costume ideas
start cleaning
wow strategy guide
World of Warcraft keybinds
Looking around
what is my car worth
Villa Rental in Mauritius
tv series for free
my cash now
Seattle property
Elder Care Bellflower CA
farms in charlottesville
medical marijuana symptoms list
Location Ile Maurice
Location Villa Ile Maurice
best photo printer
internet dating
Elder Care Homeland
audio speakers
Marketing Surrey
herman cain bumper sticker
Shopping Directory
how to be a race car driver
personal trainer tampa
Location Bungalow Ile Maurice
hotel rates
Suchmaschinenoptimierung
festkjoler
mensajes subliminales
robot aspirador
Location Villa Maurice
http://oscarmayer-coupons.net/
Cheap Amber
Self Catering Accommodation Mauritius
audio Software
Cool Shoes
Save Marriage
gamehosting
Airlines Letter That Might
vibrating plate
captain america faux bronze
Nail Salons West Jordan Utah
Bodybuilding Beginner
sub metering
Style Guide For Men And Women
Visalus Sciences
homework
Location Villa Ile Maurice
videochat
sewa innova
motorcycle ramps
herbal remedies
vendetta mask
Elder Care Bonita
HD vs SD
Schwinn 240 Recumbent Bike
Gratis Daten Zonder Inschrijven
Carpet Cleaning Missoula
handmade
hypotheekadvies amsterdam
makelaar in utrecht
testosterone
bodybuilding
creatine
street fashion
consumer forum
post free classifieds in india
michigan no fault
Drug Addiction
seo company pune
Pool table light deals
Wholesale Clothing
Tenby Carpet Cleaner
drums dvd
spletno gostovanje
Massage Chairs
Movers Los Angeles
Movers Miami
how to make money from apps
Education
surf exchange
affordable rentals
Social Worker Jobs
Africa #1 Marketplace
Black Diamond
Save My Marriage Today Review
skyrim animals
Make Money From Home
Security Camera
makita cordless drill
i need money
table saw outfeed table
cctv
PORTLAND KITCHEN REMODELING | 503.692.3115 | WAYNE S. RANDALL
Marriage Advice
Improve Rankings
air impact wrench
Hostgator Cyber Monday
the Best Workout Dvds
Global Business News
PowerPoint Classes
Stock News
top rated pre workout supplement uk
houseboats for sale
friv
Black Friday Hostgator
Tegaderm 3M
macaroni and cheeses
p90x2 results
p90x
Get a US IP address
property for sale in Spain
Cyber Monday Hosting
Sports Betting deal
ipad
Adobe Dreamweaver training courses
Office Design Services
Backcountry
hypnosis and mind control
Sporting Goods
Fat Burning Furnace
Skiing
dora_game
Motorola MBP36
Short
nigerian newspapers read them online
Biking
Black Friday Hosting
motorcycle games
How to Fix a Relationship
online health insurance
polished Gem Pearl
Web Hosting
buy phentermine
Cheap Wireless Printers
electronic cigarette review
aluminium windows
Santa Monica Spas
la digital dentistry
web services and development
investment property melbourne
pc games free download
extended warranty companies for cars
How To Buy Steroids Online
Turbulence Training Review
Authentic Leadership
letter head printing
flooring companies seneca sc
Mesothelioma lawsuit settlements
giving
watch sherlock holmes online
un cacat
requirements to be a model
Septic Tank
Evil eye jewelry
www.cna101.com
buy guaranteed twitter followers
extra money
Funny Pictures
h miracle
Dark circles
Business Directory
handicap vans
get envelopes printed
botox las vegas
Minecraft Mods
Generators for Home Use
Algarve Car Hire
coup
Henne
Office Space planning
Vancouver sushi
General Dentistry
hcg results
Fort William B&B
Transmission Parts
filesonic
weight loss tablets
  • kitchen aid toaster says:
    2011-10-25 at 12:29 pm

    Here is what i found out…

    I recommend reading this article…

  • Earache remedies says:
    2011-10-25 at 11:45 am

    Related……

    [...]just beneath, are numerous totally not related sites to ours, however, they are surely worth going over[...]……

  • doodle games says:
    2011-10-25 at 11:06 am

    Online Article……

    [...]The information mentioned in the article are some of the best available [...]……

  • driving lessons aberdeen says:
    2011-10-25 at 10:06 am

    Websites you should visit…

    [...]below you’ll find the link to some sites that we think you should visit[...]……

  • Quit Smoking Marijuana says:
    2011-10-25 at 9:07 am

    Great website…

    [...]we like to honor many other internet sites on the web, even if they aren’t linked to us, by linking to them. Under are some webpages worth checking out[...]……

  • ethernet pinout says:
    2011-10-25 at 7:06 am

    Gems form the internet…

    [...]very few websites that happen to be detailed below, from our point of view are undoubtedly well worth checking out[...]……

  • kitchen aid toaster says:
    2011-10-25 at 7:04 am

    Recent Blogroll Additions……

    [...]usually posts some very interesting stuff like this. If you’re new to this site[...]……

  • « Previous 1 2 3

    Leave a Reply:

    Click here to cancel reply.

    Name (required):
    Mail (will not be published) (required):
    Website:
    Comment (required):
    XHTML: You can use these tags: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>
    验证图片
    刷新验证码
    *

    Popular Articles

      • How to uninstall pc optimizer pro, pc optimizer pro removal 1139 comment(s)
      • what is Pbupdate.exe and how to fix Pbupdate.exe error? 1138 comment(s)

    latest comments

    • 正在加载...

    Tags

      Antivirus Suite Autorun ave.exe Backdoor Backdoor.Win32 Backdoor.Win32 removal browser home page was altered cc Clicker.dj Clunky Backdoor removal Default home page is modified DLL files error DOMDocument->load() downloader encountered Fix Kernel32 Dll Error MAC Microsoft Security Essentials PSW PSW.Kykymber.cc registry was modified remove MyWinLocker remove regedit32.exe remove safedrv.exe remove Trojan.Win32.Buzus.a Run command slow computer Speed Up Computer speed up pc Trojan Trojan-Downloader.Win32.Small.b removal Trojan-PSW.Win32 Trojan.Win32 Trojan.Win32 removal Trojan Downloader Trojan Dropper uninstall MyWinLocker variant dj Virus W32.Cervivec.A@mm Win32 Win32.Hack.GrayBird.al.761856 Win32.TrojDownloader.Guupk.ps Worm Worm.Win32

    Category

    • News
    • Others
    • Registry
    • Script
    • System Utility
    • Virus
    • Windows
    • XML

    Archives

    • December 2011
    • November 2011
    • October 2011
    • September 2011
    • July 2011
    • June 2011
    • May 2011
    • April 2011
    • March 2011
    • February 2011

    Links

    • Download Drivers

    Pages

    • Regtweaker
    • Spyware Cease
    
    Copyright © 2012 PC solutions. Powered by VersionHunter.com. registry repair |Threats Center
    Top