• Home
  • Regtweaker
  • Subscribe to Posts
  • Subscribe to comments

PC solutions

Give you Professional Suggestions

  • Home
  • News
  • Registry
  • Script
  • System Utility
  • Virus
  • Windows
  • XML
Home Virus Trojan-PSW.Win32.Magania.rxk removal

Trojan-PSW.Win32.Magania.rxk removal

Posted on Saturday, 18 June 2011
22 Comments
Share|

virus Name: trojan-PSW.Win32.Magania.rxk

Manual Solution:

1. Manually delete the following files

% SystemRoot% \ system32 \ cjvesk.dat
% SystemRoot% \ system32 \ bvkiwp1.dat
% SystemRoot% \ system32 \ bvkiwp2.dat
% SystemRoot% \ system32 \ bvkiwp3.dat
% SystemRoot% \ system32 \ bvkiwp4.dat
% SystemRoot% \ system32 \ bvkiwp5.dat
% ProgramFiles% \ hgreag \ elijnixxb.dll (random name)

Variable declaration:

% SystemDriver% system partition, usually “C: \”
% SystemRoot% WINDODWS directory, usually “C: \ Windows”
% Documents and Settings% user’s documents directory, usually “C: \ Documents and Settings”
% Temp% temp folder, usually “C: \ Documents and Settings \ current user name \ Local Settings \ Temp”
% ProgramFiles% system program the default installation directory, typically: “C: \ ProgramFiles”

Analysis of the virus:

(1), to create a snapshot of the process, through search process “360tray.exe”, “ravmond.exe”, “qqpctray.exe” process, if the sign were found.
(2) determine whether there is% SystemRoot% \ system32 \ cjvesk.dat, if you exit the program, use the file to indicate whether the machine is running a virus.
(3), were created in the system directory under the file “bvkiwp1.dat”, “bvkiwp 2.dat”, “bvkiwp 3.dat”, “bvkiwp 4.dat”, “bvkiwp 5.dat”, the configuration information are written into five files created and set to hidden attribute.
(4), create the directory “% ProgramFiles% \ hgreag \”, and in this directory, create elijnixxb.dll (random name), the release of the virus code to the file.
(5), by calling the LSP system function WSCEnumProtocols, WSCInstallProvider, WSCWriteProviderOrder network protocol installed xvzgnwowz.dll chain to the system to update the installation of all service providers in order to customize the service providers ranked in the forefront of all agreements, this winsock-based implementation, all programs are loaded xvzgnwowz.dll.
(6), and if we find there is a security system into the software process, then exit the program directly, or delete itself after exiting the program.
(7), by WSP series WSPSend () function, such as the interception of the game account passwords and other network users to send data to the hacker specified address.

Viruses create  files:

% SystemRoot% \ system32 \ cjvesk.dat
% SystemRoot% \ system32 \ bvkiwp1.dat
% SystemRoot% \ system32 \ bvkiwp2.dat
% SystemRoot% \ system32 \ bvkiwp3.dat
% SystemRoot% \ system32 \ bvkiwp4.dat
% SystemRoot% \ system32 \ bvkiwp5.dat
% ProgramFiles% \ hgreag \ elijnixxb.dll (random name)

Virus access to the network:

www.sz ***. com: 54325/anquan


Share this Post:
Digg Google Bookmarks reddit Mixx StumbleUpon Technorati Yahoo! Buzz DesignFloat Delicious BlinkList Furl
Tagged with: Trojan-PSW.Win32

22 Responses to “Trojan-PSW.Win32.Magania.rxk removal”

Trackbacks are disabled.

beyaz
car audio review
  • Robb says:
    2012-04-1 at 8:13 am

    In case you didn’t know Jeanette Winterson who once stated the quote – What you risk reveals what you value.

  • Josiah Veren says:
    2011-09-10 at 2:30 pm

    aboves…

    Thanks! Will probably be nice to anyone who usess it, including myself. Sustain the nice work for positive ill take a look at extra posts.. Hey very nice blog!! more please great….

  • free war strategy games says:
    2011-08-28 at 9:04 pm

    [...]I saw this really great post today.[...]…

    I have honestly never read such overwhelmingly good content like this. I agree with all points and ideas. This info is really great. Although unrelated to my blog, worth linking to…

  • Vehicle Warranties says:
    2011-08-21 at 3:57 am

    Car Warranty News and Reviews…

    [...]while the web sites we connect to underneath are not related to ours, but are worth checking out[...]…

  • Gutter Installation Seattle says:
    2011-08-19 at 7:14 pm

    Online Article……

    [...] ….. [...]……

  • Kasper Suits says:
    2011-08-19 at 1:16 am

    Miss America 2011…

    [...]in the following are a couple of urls to internet pages that we connect to because we think these are really worth checking out[...]…

  • iddaa tahminleri says:
    2011-08-15 at 6:55 am

    gol videoları…

    iddaa tahminleri…

  • superbahis giriş says:
    2011-08-14 at 8:24 am

    superbahis…

    superbahis giriş…

  • ukash says:
    2011-08-14 at 6:14 am

    ukash kart…

    ukash…

  • borsa says:
    2011-08-9 at 6:24 am

    borsa…

    borsa haberleri…

  • salamura depo says:
    2011-08-5 at 7:09 am

    salamura depo…

    prefabrik konutlar…

  • iki katlı prefabrik says:
    2011-08-2 at 5:50 am

    prefabrik ev…

    iki katlı prefabrik…

  • emlak ilanlari says:
    2011-07-31 at 12:26 am

    emlak…

    emlak ilanlari…

  • escort bayan says:
    2011-07-29 at 8:43 am

    oo nice work…

    very ncy…

  • müzikforum says:
    2011-07-28 at 4:42 am

    müzikforum…

    müzik forum…

  • Arabalar says:
    2011-07-27 at 12:53 pm

    Arabalar…

    Araba resimleri…

  • film izle says:
    2011-07-27 at 2:09 am

    film izle…

    dizi izle…

  • toptan mallar says:
    2011-07-22 at 2:51 am

    toptan mallar…

    toptan mallar…

  • film izle says:
    2011-07-21 at 4:30 am

    film izle…

    film izle…

  • Laser Hair Removal Cost says:
    2011-06-20 at 11:37 pm

    Thanks for this info. Every now and then this hell of a virus crashes into my computer and i am usually left with formatting my disks. but this post helped me a lot. So, thanks for sharing.
    Btw my site is . Maybe you can pay a visit.

  • Leave a Reply:

    Click here to cancel reply.

    Name (required):
    Mail (will not be published) (required):
    Website:
    Comment (required):
    XHTML: You can use these tags: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>
    验证图片
    刷新验证码
    *

    Popular Articles

      • How to uninstall pc optimizer pro, pc optimizer pro removal 1139 comment(s)
      • what is Pbupdate.exe and how to fix Pbupdate.exe error? 1138 comment(s)

    latest comments

    • 正在加载...

    Tags

      Antivirus Suite Autorun ave.exe Backdoor Backdoor.Win32 Backdoor.Win32 removal browser home page was altered cc Clicker.dj Clunky Backdoor removal Default home page is modified DLL files error DOMDocument->load() downloader encountered Fix Kernel32 Dll Error MAC Microsoft Security Essentials PSW PSW.Kykymber.cc registry was modified remove MyWinLocker remove regedit32.exe remove safedrv.exe remove Trojan.Win32.Buzus.a Run command slow computer Speed Up Computer speed up pc Trojan Trojan-Downloader.Win32.Small.b removal Trojan-PSW.Win32 Trojan.Win32 Trojan.Win32 removal Trojan Downloader Trojan Dropper uninstall MyWinLocker variant dj Virus W32.Cervivec.A@mm Win32 Win32.Hack.GrayBird.al.761856 Win32.TrojDownloader.Guupk.ps Worm Worm.Win32

    Category

    • News
    • Others
    • Registry
    • Script
    • System Utility
    • Virus
    • Windows
    • XML

    Archives

    • December 2011
    • November 2011
    • October 2011
    • September 2011
    • July 2011
    • June 2011
    • May 2011
    • April 2011
    • March 2011
    • February 2011

    Links

    • Download Drivers

    Pages

    • Regtweaker
    • Spyware Cease
    
    Copyright © 2012 PC solutions. Powered by VersionHunter.com. registry repair |Threats Center
    Top