Diskregerl.exe (TROJAN.AGENT.CDT) Virus manual killing _ virus killing
Last Update:2017-01-18
Source: Internet
Author: User
File md5:e98a4571cf72b798077d12d6c4894629
Behavioral Analysis:
1. Copy files:
C:\windows\system32\diskregerl.exe 45,056 bytes
2, no Add Startup item action.
3. Release 2 Batches:
The content is:
22483
17213
25187
6133
22690
25373
Date 2004-08-17
19477
Time 20:00:00
Ping 127.0.0.1-n 5
Sc.exe Create Diskregerl binpath= "C:\windows\system32\diskregerl.exe-kills" type= own type= interact start= Auto Display Name= Diskregerl Programnot
Sc.exe Description Diskregerl Create a network connection 2
regsvr32.exe/u/S Scrrun.dll
regsvr32.exe/u/S Shimgvw.dll
regsvr32.exe/u/S Itss.dll
regsvr32.exe/u/S Vbscript.dll
REGSVR32.EXE/S Jscript.dll
reg.exe Delete hklm\system\controlset001\control\safeboot\minimal\{4d36e967-e325-11ce-bfc1-08002be10318}/F
reg.exe Delete hklm\system\controlset001\control\safeboot\network\{4d36e967-e325-11ce-bfc1-08002be10318}/F
reg.exe Delete hklm\system\currentcontrolset\control\safeboot\minimal\{4d36e967-e325-11ce-bfc1-08002be10318}/F
reg.exe Delete hklm\system\currentcontrolset\control\safeboot\network\{4d36e967-e325-11ce-bfc1-08002be10318}/F
Reg.exe Delete hklm\software\microsoft\windows\currentversion\run/f
23413
Sc.exe start Diskregerl
Del "C:\WINDOWS\Media\Windows XP started. wav"
Del "C:\WINDOWS\Media\Windows XP Information Bar. wav"
Del "C:\WINDOWS\Media\Windows XP pop-up window blocked. wav"
REGSVR32.EXE/S C:\windows\system32\Programnot.dll
Ping 127.0.0.1-n 6
Del "C:\Documents and Settings\ lonely more reliable \ Desktop \oky.exe"/F
22483
17213
Date 2008-04-02
Time 08:21:33
Del%0
Exit
The second one:
25187
6133
226902537319477
2819720092
404
Ping 127.0.0.1-n 16
13539
CMD.EXE/C del/f/s/q C:*.gho
6752
CMD.EXE/C del/f/s/q D:*.gho
31772
CMD.EXE/C del/f/s/q E:*.gho
12028
CMD.EXE/C del/f/s/q F:*.gho
8720
CMD.EXE/C del/f/s/q G:*.gho
10731
CMD.EXE/C del/f/s/q H:*.gho
8840
CMD.EXE/C del/f/s/q I:*.gho
11736
REGSVR32.EXE/S C:\windows\system32\Programnot.dll
Del%0
Exit
4, connect the website, brush flow:
http://www.xerty.cn/^^/300center.htm
5, in addition, the virus may maliciously lock IE homepage, but not implemented.
Workaround:
1, restart the computer.
2, delete the file:
C:\windows\system32\diskregerl.exe
3, if the virus can not be deleted after reboot, please download the ice blade (the software can be downloaded to down.45it.com), to end its process.