
| Aliases | |||
|---|---|---|---|
| Typical Symptoms | |||
| Discovered | [korea] 2008-03-14 [Foreign] 0000-00-00 |
||
| Type | Trojan Horse | ActiveField | Win32 |
| Destory/Distribution | ![]() ![]() |
||
| Origin | others | Encryption | NO |
| Location | File | Memory residence | NO |
| Scan engine needed |
2008-03-14 [Able to detect & repair]
|
||
[Symptom of Infection] 1. It creates files to below path. C:\WINDOWS\system32\svchst.exe
2. It adds registry like below. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\Info: "http://136169.10wl.net.cn/ip.txt>136169>上线>远程上线主机 >41>0>1080>guest>123456>C:\DOCUME~1\who\LOCALS~1\Temp\IXP000.TMP\1.exe>"
3. It tries to access to a certain site. |
[How to repair] 1. If you are WinXP/ME users, please be inactivate System Recovery Function. The reason why being inactivate of the system recovery is to clean the virus completely. - Use the trial version of ViRobot products (30days only) a. Run your ViRobot, and choose "all files" in scan option. - ViRobot Desktop 5.5 : [Tools] -> [Configuration] -> [Virus Scan] : Check all files - LiveCall (Free Scan) : [Advanced Scan] : Check |