Virus Analysis Report: Rogue software 3448

Source: Internet
Author: User
Tags safe mode

This is a virus written using [Borland C + +]

After the system is infected, open IE or other browser start page has been tampered with as hxxp://wxw.3448.c0m/.

Viruses protect themselves by using API hooks.

Download and execute through other malicious programs or downloads, using random file names to achieve the masking filename cleanup mode.

After the virus has run the following behavior:

First, the virus by modifying the registry SOFTWARE\Microsoft\Windows\CurrentVersion\Run to achieve the automatic operation of the boot.

The virus is mainly loaded by Rundll32.exe.

Virus also infects Tencent QQ TimProxy.dll file import table, can be loaded when users start QQ.

After loading, use the message hooks to inject the processes and do different actions according to the process name.

The main are:

1. Hook process API, self protection.

2, injected in the QQ.EXE process, only do modify the registry action.

3, injected in the EXPLORER.EXE process of the virus mainly to do the action.

(1) The main damage registry Safeboot key, resulting in access to safe mode.

(2) downloading files and updating them by file type, running or replacing hosts files.

(3) Infected Tencent QQ TimProxy.dll file import table.

The virus that is loaded via Rundll32.exe will copy itself to the system directory (%systemdir%) and the driver directory (%systemdir%\drivers\).

Third, modify the registry key values below:

注册表键:Software\Microsoft\Internet Explorer\Main
数据项:"Start Page"
数据值为:"http://www.3448.com"
注册表键:Software\Microsoft\Internet Explorer\Search
数据项:"CustomizeSearch"
数据值为:"http://www.3448.com"
注册表键:Software\Microsoft\Internet Explorer\Search
数据项:"SearchAssistant"
数据值为:"http://www.3448.com"

Search the process name or the window text contains the following string of processes, and then turn off the computer after discovery.

hsreg.exe
xiufuhosts
hs.exe
yaass
filemon
regmon
wopticlean
4199_9505
4199 9505
41999505
95054199
9505专杀
删除9505
4199.com/9505.com
kickthemout
流氓软件清除
system repair
btbaicai.com
wopticlean
icesword
3448专杀
清除3448
删除3448
3448病毒
unlocker
killbox
hijack
ollydbg
ewido anti-spyware
文件寻找 1.0
黄山IE
瑞星卡卡
安全卫士

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.