• Home
  • Regtweaker
  • Subscribe to Posts
  • Subscribe to comments

PC solutions

Give you Professional Suggestions

  • Home
  • News
  • Registry
  • Script
  • System Utility
  • Virus
  • Windows
  • XML
Home Virus What is sWsinHelp32.exe and how to remove it

What is sWsinHelp32.exe and how to remove it

Posted on Tuesday, 28 September 2010
214 Comments
Share|

backdoor: Backdoor.Win32.Agent.qew

Risk level: Medium

virus Description

The sample is a backdoor developed by the “C / C++”, using “NsPack” packers approach attempts to evade signature scanning, after it is packed size is “20,992″ bytes, the icon is “”, viruses extension “exe” , mainly through the “file bundle”, “download manager”, “page linked to horse”, etc. to spread, the viruses primary purpose is to control the user’s computer.
After the user’s computer was infected, there will be no reason to open network ports, network Slow, data loss and so on for no reason.

Infection in the operating system

Windows 2000/Windows XP / Windows 2003/Windows Vista / Windows 7

Transmission

Bundle file, web page linked to horse, download tools to download

Manual removal:

1, manually stop item of  service called “Windsows Help System”

2, manually delete the following Registry key:
HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Services \ WinHselp32
Name: ImagePath
Value: C: \ WINDOWS \ system32 \ sWsinHelp32.exe
HKEY_LOCAL_MACHINE \ SYSTEM \ ControlSet001 \ Services \ WinHselp32
Name: ImagePath
Value: C: \ WINDOWS \ system32 \ sWsinHelp32.exe
3, manually delete the following file:
% SystemRoot% \ system32 \ sWsinHelp32.exe

Variable declaration:

% SystemDriver% partition where the system is, usually “C: \”
% SystemRoot% WINDODWS directory, usually “C: \ Windows”
% Documents and Settings% user file directory, usually “C: \ Documents and Settings”
% Temp% temp folder, usually “C: \ Documents and Settings \ current user name \ Local Settings \ Temp”
% ProgramFiles% system program the default installation directory, typically: “C: \ ProgramFiles”

Analysis of the virus

(1) virus for their own path to copy itself to % SystemRoot% \ system32 \ sWsinHelp32.exe.
(2) When the copy is complete, set its property ot the system to hide and run.
(3) call the command line to delete the virus itself
(4)% SystemRoot% \ system32 \ sWsinHelp32.exe open the Services Manager, will add itself to the name “WinHselp32” item of service, the service item display name to “Windsows Help System”, the corresponding registry key is:
HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Services \ WinHselp32
Name: ImagePath
Value: C: \ WINDOWS \ system32 \ sWsinHelp32.exe
HKEY_LOCAL_MACHINE \ SYSTEM \ ControlSet001 \ Services \ WinHselp32
Name: ImagePath
Value: C: \ WINDOWS \ system32 \ sWsinHelp32.exe
(5) start the service after successful entry
(6) the service item entry in the virus injected into the svchost.exe and running, connect to the specified network, transfer the user’s computer’s operating system version and MAC address information and wait for hackers to further control commands.

Virus to create a file:

% SystemRoot% \ system32 \ sWsinHelp32.exe

Virus delete files:

Virus source

Virus to create the registry:

HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Services \ WinHselp32
Name: ImagePath
Value: C: \ WINDOWS \ system32 \ sWsinHelp32.exe
HKEY_LOCAL_MACHINE \ SYSTEM \ ControlSet001 \ Services \ WinHselp32
Name: ImagePath
Value: C: \ WINDOWS \ system32 \ sWsinHelp32.exe

Virus to access the network:

122.225 .***. 189:80
122.225 .***. 146:8080


Share this Post:
Digg Google Bookmarks reddit Mixx StumbleUpon Technorati Yahoo! Buzz DesignFloat Delicious BlinkList Furl
Tagged with: Backdoor.Win32.Agent.qew, remove sWsinHelp32.exe, sWsinHelp32.exe, sWsinHelp32.exe virus

214 Responses to “What is sWsinHelp32.exe and how to remove it”

Trackbacks are disabled.

Coping Techniques For Stress
vistaril for anxiety
bikram yoga calories burned
best way to lose belly fat for women
woman fashion boots
Wesley Chapel Carpet Cleaners
Track Internet Usage
link building
More Traffic
one new man
one new man
synthetic spice
financial help for single mothers
free cna training online
Sizzling Hot
fontanna czekoladowa
mlm lead generation
Garmin Forerunner 305
Buy Real Facebook Fans
Mr Nice Guy
plant olive tree
Nike Golf Equipment
Better Weather
sports social network
lonely
britax 85
druckerei
download ebooks
playground sets
party rentals
security essentials
How do i get a tax return
edinburgh to london flights
window replacement Colorado Springs
reverse phone directory
Target Promotion Code
professional cheap website traffic service
find government records
Front Core Capital Gold Market
gafas de sol carrera
business insurance
how to flip a house
enter your email
business card maker
gps tracker for car
farmville hacks
resume objective
games and consoles
family video
name
name
problem solver
radian car seat
george foreman family grill
best motherboard
E-bike
Microfinance
9500ci Passport Radar Detector
pat testing
sailing in san blas
family camping
natural treatment for anxiety
dubai middle east travel
special education marin county
{pozycjonowanie|pozycjonowanie stron}
dubturbo
water conservation gifts
home builders utah
film television comedy
penny auctions
discount vouchers
Medicare Quote
karma dla psów
Barter
sterowniki plc
AC Motor Repair
facebook
Darmowy katalog
Dobre katalogi
Dobre katalogi
Dobre katalogi
Darmowe katalogi
AKO Webmail
diabetes cure
Ubezpieczenia AC
Games
Individualus Anglu Kalbos Kursai
czekoladowa fontanna
Prince lion Opinie
adult toys
neil asher
fontanny czekoladowe
Folia stretch
  • razor scooter reviews says:
    2012-02-29 at 6:55 am

    Hi my friend! I wish to say that this article is amazing, great written and include almost all significant infos. I would like to see more posts like this .

  • Roof U Values says:
    2011-10-24 at 10:26 pm

    Funny Thing Happened…

    While I was enjoying the blog item, a bear just killed my pet cricket!…

  • Travel Fiji Packages says:
    2011-10-24 at 4:51 pm

    I’ve been brain vampired…

    There went 39 IQ points, gone by reading this blog post….

  • Lodges On Loch Lomond says:
    2011-10-24 at 1:41 pm

    Chores not getting done…

    I found my niece skimming your website instead of doing their chores….

  • IFRS Exam says:
    2011-10-23 at 10:01 pm

    Treasured…

    I seriously awesome this item!…

  • WoW Gold kaufen says:
    2011-10-23 at 3:47 pm

    WoW Gold kaufen…

    [...]usually posts some really fascinating stuff like this. If you?re new to this site[...]…

  • Walnut Glazed Doors says:
    2011-10-15 at 11:02 pm

    News info…

    I was reading the news and I saw this really cool information…

  • test says:
    2011-10-15 at 1:04 pm

    Want To Get Rid Of Money Problems…

    [...]If you are conscious when working at your projects you will do more than if you have no ideas..[...]…

  • Wood Blinds says:
    2011-10-11 at 2:38 pm

    Looking around…

    I like to look around the internet, often I will just go to Stumble Upon and read and check stuff out…

  • dating personals says:
    2011-10-11 at 8:49 am

    jewish dating…

    These people will control ones own everyday living with thier effect….

  • reebok zig kids says:
    2011-10-8 at 12:41 am

    Tumblr article…

    I saw someone writing about this on Tumblr and it linked to…

  • http://zenmed.com says:
    2011-10-6 at 12:32 am

    Great website…

    [...]we like to honor many other internet sites on the web, even if they aren’t linked to us, by linking to them. Under are some webpages worth checking out[...]……

  • home remedies for indigestion says:
    2011-10-5 at 8:08 pm

    heartburn treatments…

    You should check this out……

  • My best blog here... says:
    2011-10-5 at 7:28 am

    Another Title…

    I saw this really good post today….

  • unlock iphone says:
    2011-10-1 at 5:46 am

    Amazing…

    Thank you for provide good information about this, this content must be write by expert…

  • Fb Fan says:
    2011-09-30 at 5:53 am

    Recommended Websites…

    [...]below you’ll find the link to some sites that we think you should visit[...]…

  • Symptoms Of Low Vitamin D says:
    2011-09-30 at 4:40 am

    Symptoms Of Low Vitamin D…

    please visit the sites we follow, including this one, as it represents our picks from the web…

  • work on the internet says:
    2011-09-22 at 5:40 pm

    work on the internet…

    [...]although sites we backlink to beneath are considerably not related to ours, we feel they’re in fact worth a go by, so have a look[...]…

  • English bulldog puppy for sale says:
    2011-09-20 at 10:56 pm

    English bulldog puppy for sale…

    [...]we prefer to honor numerous other online websites around the web, even when they aren?t linked to us, by linking to them. Under are some webpages worth checking out[...]…

  • xxx says:
    2011-09-20 at 7:47 pm

    xxx…

    [...]Sites of interest we have a link to[...]…

  • Google Search says:
    2011-09-17 at 9:56 pm

    Google Search…

    [...]check beneath, are some totally unrelated internet sites to ours, even so, they may be most trustworthy sources that we use[...]…

  • « Previous 1 2 3

    Leave a Reply:

    Click here to cancel reply.

    Name (required):
    Mail (will not be published) (required):
    Website:
    Comment (required):
    XHTML: You can use these tags: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>
    验证图片
    刷新验证码
    *

    Popular Articles

      • How to uninstall pc optimizer pro, pc optimizer pro removal 1139 comment(s)
      • what is Pbupdate.exe and how to fix Pbupdate.exe error? 1138 comment(s)

    latest comments

    • 正在加载...

    Tags

      Antivirus Suite Autorun ave.exe Backdoor Backdoor.Win32 Backdoor.Win32 removal browser home page was altered cc Clicker.dj Clunky Backdoor removal Default home page is modified DLL files error DOMDocument->load() downloader encountered Fix Kernel32 Dll Error MAC Microsoft Security Essentials PSW PSW.Kykymber.cc registry was modified remove MyWinLocker remove regedit32.exe remove safedrv.exe remove Trojan.Win32.Buzus.a Run command slow computer Speed Up Computer speed up pc Trojan Trojan-Downloader.Win32.Small.b removal Trojan-PSW.Win32 Trojan.Win32 Trojan.Win32 removal Trojan Downloader Trojan Dropper uninstall MyWinLocker variant dj Virus W32.Cervivec.A@mm Win32 Win32.Hack.GrayBird.al.761856 Win32.TrojDownloader.Guupk.ps Worm Worm.Win32

    Category

    • News
    • Others
    • Registry
    • Script
    • System Utility
    • Virus
    • Windows
    • XML

    Archives

    • December 2011
    • November 2011
    • October 2011
    • September 2011
    • July 2011
    • June 2011
    • May 2011
    • April 2011
    • March 2011
    • February 2011

    Links

    • Download Drivers

    Pages

    • Regtweaker
    • Spyware Cease
    
    Copyright © 2012 PC solutions. Powered by VersionHunter.com. registry repair |Threats Center
    Top