
| Aliases | |||
|---|---|---|---|
| Typical Symptoms | Changes registry,,Installing Trojan Horse,Creates file | ||
| Discovered | [korea] 0000-00-00 [Foreign] 0000-00-00 |
||
| Type | Trojan Horse | ActiveField | Win32 |
| Destory/Distribution | ![]() ![]() |
||
| Origin | others | Encryption | NO |
| Location | File | Memory residence | NO |
| Scan engine needed |
2010-07-23 [Able to detect & repair]
|
||
[Symptom of Infection] http://twitter.com/adrxxxxxx_82 http://me2day.net/adrxxxxxx_82 http://11x.1xx.15x.x47/upload/atk.exe http://11x.1xx.15x.x47/upload/fm.exe http://11x.1xx.15x.x47/upload/prvupdtcln.exe
"Type"=dword:00000010 "Start"=dword:00000002 "ErrorControl"=dword:00000001 "ImagePath"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,00,53,00,\ 5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,00,76,00,63,\ 00,68,00,6f,00,73,00,74,00,20,00,2d,00,6b,00,20,00,63,00,73,00,00,00 "DisplayName"="Windows Net Manager" "ObjectName"="LocalSystem" "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 63,00,73,00,75,00,70,00,64,00,74,00,2e,00,64,00,6c,00,6c,00,00,00 Trojan.Win32.Malex.184320 Trojan.Win32.S.Agent.100864 Trojan.Win32.S.Agent.101376 Trojan.Win32.S.Agent.494080 Worm.Win32.P2P-Palevo.D.Gen |
[How to repair]
1. If you are WinXP/ME users, please be inactivate System Recovery Function. The reason why being inactivate of the system recovery is to clean the virus completely. 2. Update the engine module for the latest one. a. ViRobot products users b. Non-ViRobot products users - Use the trial version of ViRobot products (30days only) 3. How to scan the virus.
- ViRobot Desktop 5.0 : [Tools] -> [Configuration] -> [Virus Scan] : Check all files - ViRobot Desktop 5.5 : [Tools] -> [Configuration] -> [Virus Scan] : Check all files - LiveCall (Free Scan) : [Advanced Scan] : Check b. Repair all viruses detected. c. If [Auto-repair after rebooting] message shows up, please try to re-scan after rebooting the PC. |