
| Aliases | |||
|---|---|---|---|
| Typical Symptoms | Download Malicious code,malicious action,Unable to delete the files | ||
| Discovered | [korea] 2010-01-20 [Foreign] 0000-00-00 |
||
| Type | Keylogger | ActiveField | |
| Damage/Distribution | ![]() ![]() |
||
| Origin | others | Encryption | NO |
| Target of infection | Webpage,Installed with Aplicatoin,Execution | ||
| Scan engine needed |
2010-01-20 [Able to detect & repair]
|
||
[Symptom of Infection] [KeyLogger.Qmexil.121815219] is a KeyLogger and it induces users to download it from P2P site or blog. [PIC 1] Executing Feature
<File> [KeyLogger.Qmexil.121815219] creates files like below. (Programs Folder)\222.exe (System Folder)\0005248b.ini (System Folder)\(Random Name).DLl (System Folder)\(Random Name).key (Root Folder)\google1.log <Registry> [KeyLogger.Qmexil.121815219] creates registry like below. HKLM\SYSTEM\CurrentControlSet\Services\qmexil HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_QMEXIL HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_QMEXIL HKLM\SYSTEM\ControlSet001\Services\qmexil HKLM\SYSTEM\ControlSet002\Services\qmexil HKLM\SYSTEM\ControlSet003\Services\qmexil HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion SvcHost Name: qmexil Value: qmexil <Notation> - "(Programs Folder)" could be different by OS and generally this is "C:\Program Files". - "(System Folder)" could be different by OS and generally this is "C:\Windows\System32". |
[How to repair] 1. If you are WinXP/ME users, please be inactivate System Recovery Function.
|