
| Aliases | |||
|---|---|---|---|
| Typical Symptoms | Changes registry,Place malicious code,Downloading a particular file,Destroys file | ||
| Discovered | [korea] 2010-01-21 [Foreign] 0000-00-00 |
||
| Type | Others | ActiveField | Win32 |
| Destory/Distribution | ![]() ![]() |
||
| Origin | others | Encryption | NO |
| Location | None | Memory residence | NO |
| Scan engine needed |
2010-01-21 [Able to detect & repair]
|
||
[Symptom of Infection]
(System Folder)\bdhook.dll (System Folder)\psmchd.dll (System Folder)\udhook.dll (System Folder)\schedsvc.dll (Patched) (System Folder)\cryptsvc.dll (Patched) (System Folder)\mpr.dll (normal) (System Folder)\mscrypt.dll (normal) (System Folder)\spoolsv.exe (normal) (System Folder)\svcsam.dll (normal)
3. By deleting firewall registry, it interrupts the normal execution of firewall service. 4. It downloads a certain file from http://hxtxoxm.xlxgxn.cx.xr (1x0.x5.1x7.2x3). |
[How to repair] 1. If you are WinXP/ME users, please be inactivate System Recovery Function. The reason why being inactivate of the system recovery is to clean the virus completely. - Use the trial version of ViRobot products (30days only) a. Run your ViRobot, and choose "all files" in scan option. - ViRobot Desktop 5.5 : [Tools] -> [Configuration] -> [Virus Scan] : Check all files - LiveCall (Free Scan) : [Advanced Scan] : Check |