
| Aliases | |||
|---|---|---|---|
| Typical Symptoms | |||
| Discovered | [korea] 0000-00-00 [Foreign] 0000-00-00 |
||
| Type | Virus | ActiveField | Win32 |
| Destory/Distribution | ![]() ![]() |
||
| Origin | others | Encryption | NO |
| Location | File | Memory residence | NO |
| Scan engine needed |
2010-01-21 [Able to detect & repair]
|
||
[Symptom of Infection] 1. It creates files to below path.
(User Temp Folder)\[Random].tmp (User Folder)\My Documents\database.mdb (Windows Folder)\:Microsoft Office Update for Windows XP
2. It creates below shortcut files to all drive folders. Microsoft.lnk
3. The shortcut files are connected to executed files, and they works for executing malicious code.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Explorer" = "Wscript.exe //e:VBScript "(User Folder)\My Documents\database.mdb""
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableRegistrytools" = 1 [Notation] - "(User Folder)" could be different by system and generally this is "C:\Documents and Settings\Account name"
- "(Windows Folder)" could be different by system, and generally this is "C:\Windows (Windows 95/98/ME/XP), C:\WinNT (Windows NT/2000)". |
[How to repair] 1. If you are WinXP/ME users, please be inactivate System Recovery Function. The reason why being inactivate of the system recovery is to clean the virus completely. - Use the trial version of ViRobot products (30days only) a. Run your ViRobot, and choose "all files" in scan option. - ViRobot Desktop 5.5 : [Tools] -> [Configuration] -> [Virus Scan] : Check all files - LiveCall (Free Scan) : [Advanced Scan] : Check |