
| Aliases | |||
|---|---|---|---|
| Typical Symptoms | Changes registry,Place malicious code | ||
| Discovered | [korea] 0000-00-00 [Foreign] 0000-00-00 |
||
| Type | Virus | ActiveField | Win32 |
| Destory/Distribution | ![]() ![]() |
||
| Origin | others | Encryption | NO |
| Location | Macro | Memory residence | NO |
| Scan engine needed |
2010-07-09 [Able to detect & repair]
|
||
[Symptom of Infection]
977o.dll.vir - Trojan.Win32.S.Downloader.159744.D
3. It creates JOB file to job scheduling folder. Scheduled job executes Adware.Rugo.684032. - "(Job Scheduling Folder)" could be different by system, and generally this is "C:\WINDOWS\Tasks (Windows95/98/Me), C:\WINDOWS\Tasks (Windows NT/2000), C:\WINDOWS\Tasks (Windows XP)". |
[How to repair] 1. If you are WinXP/ME users, please be inactivate System Recovery Function. The reason why being inactivate of the system recovery is to clean the virus completely. - Use the trial version of ViRobot products (30days only) a. Run your ViRobot, and choose "all files" in scan option. - ViRobot Desktop 5.5 : [Tools] -> [Configuration] -> [Virus Scan] : Check all files - LiveCall (Free Scan) : [Advanced Scan] : Check |