Do not kavo.exe kill manually can remove the virus

Source: Internet
Author: User
File name: Kavo.exe
File Size: 116464 bytes

AV name:

TROJAN-PSW.WIN32.ONLINEGAMES.PCM (Kaspersky)

Trojan.PSW.Win32.GameOL.lor (Rising)

WORM/AUTORUN.Y (AVG)



Written Language: Delphi



File md5:3b08963e3b2cae9e3b4dc38b21b2a69d



Virus type: Theft Trojan



Behavioral Analysis:



1, release the virus file:



C:\WINDOWS\system32\kavo.exe 113759 bytes

C:\WINDOWS\system32\kavo0.dll 96768 bytes

C:\WINDOWS\system32\kavo1.dll 96768 bytes



2, add the registry, boot:



HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run

Kava = REG_SZ, "C:\windows\system32\kavo.exe"



3, modify the registry, record the version of the download address:



Hkey_classes_root\clsid\madown

is currently: "cdfty1.7"



4, start IE process, connect network download Trojan, release:



C:\WINDOWS\system32\tavo.exe

C:\WINDOWS\system32\tavo0.dll



5, Tavo0.dll and Kavo1.dll are injected into the system process, monitor the mouse, keyboard operation, theft Trojan.



6, release the driver, randomly named, and then delete itself.



7, modify the registry, destroy the display hidden file function.



8, traverse the disk, generate virus files and Autorun.inf



Workaround:



1, download the Sreng, and then disconnect the network.



2, open Sreng, delete registry key:



(registry value) Kava and (registry value) Tava



3, restart the computer, delete files:



C:\WINDOWS\system32\kavo.exe 113759 bytes

C:\WINDOWS\system32\kavo0.dll 96768 bytes

C:\WINDOWS\system32\kavo1.dll 96768 bytes

C:\WINDOWS\system32\tavo.exe

C:\WINDOWS\system32\tavo0.dll



There are also Autorun.inf and virus files on each disk, also deleted, recommended with WinRAR



4. Other:



Modify Registry Repair Show hidden file features:



HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced

(*) (registry value) Hidden

REG_DWORD, 2 modified to REG_DWORD, 1

(*) (registry value) ShowSuperHidden

REG_DWORD, 0 modified to REG_DWORD, 1



Hkey_local_machine\software\microsoft\windows\currentversion\explorer\advanced\folder\hidden\showall

(*) (registry value) CheckedValue

REG_DWORD, 0 modified to REG_DWORD, 1

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.