• Home
  • Regtweaker
  • Subscribe to Posts
  • Subscribe to comments

PC solutions

Give you Professional Suggestions

  • Home
  • News
  • Registry
  • Script
  • System Utility
  • Virus
  • Windows
  • XML
Home Virus remove Backdoor.Win32.Yoddos.cc guide

remove Backdoor.Win32.Yoddos.cc guide

Posted on Saturday, 14 May 2011
19 Comments
Share|

virus Name: backdoor.Win32.Yoddos.cc

Risk level: Medium

Virus Description

The virus is mainly through the “file bundle”, “download tool to download”, “web page linked to horse”, etc. to spread, the viruses is designed to control the user’s computer, the user’s computer virus, the computer will appear to run Slow, Unknown process and so on.

Infection in the operating system
Windows 2000/Windows XP / Windows 2003/Windows Vista / Windows 7

Transmission

Bundle file, web page linked to horse, download tools to download

Manual Solution:

1, manually delete the following files:
Manually delete the% Systemroot% \ system32 \ winhelp32.exe,
% SystemDriver% \ 2.exe

2, manually delete the following Registry key:
HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Services \ WinHelp32 service items

Variable declaration:

% SystemDriver% system where the partition, usually “C: \”
% SystemRoot% WINDODWS directory, usually “C: \ Windows”
% Documents and Settings% user file directory, usually “C: \ Documents and Settings”
% Temp% temp folder, usually “C: \ Documents and Settings \ current user name \ Local Settings \ Temp”
% ProgramFiles% system program the default installation directory, typically: “C: \ ProgramFiles”
Analysis of the virus

(1), check whether there kmon.dll (Rising card), if the release of the dll module.
(2), compared with its own whether the% Systemroot% \ system32 \ svchost.exe, if not to compare themselves whether the% Systemroot% \ system32 \ winhelp32.exe, if not, copies itself to% Systemroot% \ system32 \ winhelp32.exe , and set the hidden attribute.
(3) try to start the service, if the startup fails, for the% Systemroot% \ system32 \ WinHelp32.exe created called “Windows Help System” service. Corresponding to the service to start the service and create a registry key HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Services \ WinHelp32.
(4), the service starts successfully, create a thread, from hackers to download the file to the specified URL% SystemDriver% \ 2.exe, create a process execution 2.exe.
(5), try to inject svchost.exe, if injected into successful, run the% Systemroot% \ system32 \ winhelp32.exe, then hide the window mode cmd command to delete itself.
(6) to obtain the system version, CPU type and other information to the hacker, resolve IP address of the remote domain, and with the IP to connect, the local machine completely under the control of hackers.

Virus to create a file:

% Systemroot% \ system32 \ winhelp32.exe

Virus to create the registry:

HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Services \ WinHelp32
Name: ImagePath
Value:% Systemroot% \ system32 \ winhelp32.exe

Virus to access the network:

http://naver .*****. net: 360/index.htm.exe
pay ** 1.3322.org


Share this Post:
Digg Google Bookmarks reddit Mixx StumbleUpon Technorati Yahoo! Buzz DesignFloat Delicious BlinkList Furl
Tagged with: Backdoor, Backdoor.Win32.Yoddos.cc removal, Clunky Backdoor removal

19 Responses to “remove Backdoor.Win32.Yoddos.cc guide”

Trackbacks are disabled.

Gieringer OH flat roofing
paradgata les champs elysees
paris disneyland
refridgerator repair Valley Cottage NJ
gutters Xenia OH
  • buddist tempel hongkong says:
    2011-09-29 at 4:45 pm

    buddist tempel hongkong…

    [...]z I need to set up wordpess through a webhost. I know i have to download word 5b[...]…

  • stränder kring amsterdam says:
    2011-09-29 at 7:15 am

    stränder kring amsterdam…

    [...]q Just added this site to my bookmarks. I enjoy reading your sites and hope y kf[...]…

  • van gogh holland says:
    2011-09-29 at 6:37 am

    van gogh holland…

    [...]s Hmmm that was weird, my comment seems to have been eaten. Anyway I wanted t ah[...]…

  • fakta hongkong says:
    2011-09-28 at 1:28 pm

    fakta hongkong…

    [...]w Very few sites that happen to be detailed below, from our point of view are eb[...]…

  • free pouring bartender says:
    2011-09-28 at 6:00 am

    free pouring bartender…

    [...]r I am visiting this place for the first time. I have come to know a lot of i uy[...]…

  • online maç izle says:
    2011-08-15 at 6:23 am

    iddaa programı…

    canlı maç izle…

  • ukash says:
    2011-08-14 at 6:54 am

    ukash kart…

    ukash…

  • Macera filmi izle says:
    2011-08-11 at 6:32 am

    Aksiyon filmi izle…

    Macera filmi izle…

  • borsa says:
    2011-08-9 at 6:12 am

    borsa…

    borsa haberleri…

  • konteyner says:
    2011-08-6 at 6:48 am

    konteyner…

    konteynerler…

  • konteynernerler says:
    2011-08-2 at 2:55 am

    konteynernerler…

    konteyner özellikleri…

  • Cazibeli resim says:
    2011-07-27 at 5:12 am

    Cazibeli resim…

    Cazbeli resimler…

  • moda says:
    2011-07-27 at 12:57 am

    dekorasyon…

    moda…

  • film izle says:
    2011-07-21 at 4:05 am

    film izle…

    film izle…

  • Leave a Reply:

    Click here to cancel reply.

    Name (required):
    Mail (will not be published) (required):
    Website:
    Comment (required):
    XHTML: You can use these tags: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>
    验证图片
    刷新验证码
    *

    Popular Articles

      • How to uninstall pc optimizer pro, pc optimizer pro removal 1139 comment(s)
      • what is Pbupdate.exe and how to fix Pbupdate.exe error? 1138 comment(s)

    latest comments

    • 正在加载...

    Tags

      Antivirus Suite Autorun ave.exe Backdoor Backdoor.Win32 Backdoor.Win32 removal browser home page was altered cc Clicker.dj Clunky Backdoor removal Default home page is modified DLL files error DOMDocument->load() downloader encountered Fix Kernel32 Dll Error MAC Microsoft Security Essentials PSW PSW.Kykymber.cc registry was modified remove MyWinLocker remove regedit32.exe remove safedrv.exe remove Trojan.Win32.Buzus.a Run command slow computer Speed Up Computer speed up pc Trojan Trojan-Downloader.Win32.Small.b removal Trojan-PSW.Win32 Trojan.Win32 Trojan.Win32 removal Trojan Downloader Trojan Dropper uninstall MyWinLocker variant dj Virus W32.Cervivec.A@mm Win32 Win32.Hack.GrayBird.al.761856 Win32.TrojDownloader.Guupk.ps Worm Worm.Win32

    Category

    • News
    • Others
    • Registry
    • Script
    • System Utility
    • Virus
    • Windows
    • XML

    Archives

    • December 2011
    • November 2011
    • October 2011
    • September 2011
    • July 2011
    • June 2011
    • May 2011
    • April 2011
    • March 2011
    • February 2011

    Links

    • Download Drivers

    Pages

    • Regtweaker
    • Spyware Cease
    
    Copyright © 2012 PC solutions. Powered by VersionHunter.com. registry repair |Threats Center
    Top