Trojan. PSW. Win32.Mapdimp. a Analysis Report

Source: Internet
Author: User

Virus analysis:

The virus is written in Delphi, and upack0.39 is shelled.

The virus has the following behaviors:

1. The virus releases midimap ??. Dll and midimap ??. Dat files to the system directory (?? Represents two random letters ).

We can first use the Windows Search function to search for midimap in the system directory ??. Dll file (Note: midimap. dll is not a virus and must be followed by two random letters and midimap ??. Dll and midimap ??. Dat is a pair of viruses.) Figure 1


(Figure 1)

2. The virus also modifies the registry information for automatic loading upon startup.
HKEY_LOCAL_MACHINESOFTWAREClassesCLSID {4F4F0064-71E0-4f0d-0018-708476C7815F} points to midimap ??. Dll file

Start-run-enter regedit to open the Registry Editor:
HKEY_LOCAL_MACHINESOFTWAREClassesCLSID
Search for the following subkeys for {4F4F0064-71E0-4f0d-0018-708476C7815F }.
If you expand the sub-key, the sub-key points to the virus file % systemroot % system32midimap ??. Dll 2


(Figure 2)

If you see the midimap ??. If the dll file name is the same as the file you just searched for, it proves that it is poisoned. Figure 3


(Figure 3)

3. In addition, a friend familiar with Process Explorer can also use Process cyclerto check whether there is a midimap in the thread of assumer.exe ??. Dll 4


(Figure 4)

4. After the virus runs, the hacker will visit the website specified by the hacker to download other Trojan viruses, steal the online game account, and send the stolen information to the hacker in the background, so as to damage the interests of online game players.

Manual Handling Method:

Step 1: delete a virus file:

Use wsyscheck to manage files. Go to the system directory (c: windowssystem32 by default) and find midimap ??. Dll and midimap ??. Dat file, right-click the file, and select "send to restart Delete list ".

Step 2: delete the registry key value modified by the virus:

1. Use the wsyscheck tool or the Registry Editor to delete the following key values:
The value of HKEY_LOCAL_MACHINESOFTWAREClassesCLSID {4F4F0064-71E0-4f0d-0018-708476C7815F} is "c: windowssystem32midimap ??. Dll"

2. restart the computer.

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.