I thought for a long time that viptray is the driver of a Samsung notebook in my computer (vptray is the process name of NORTON Antivirus Software). As a result, I checked it online today and it turned out to be a virus, A lot of people are already in the middle. The strange thing is that such a big virus did not even find the coffee or the card, which surprised me!
Finally, I found the exclusive method as follows:
Download the kv_viptray.exe viptray.exe kill program.
After the download, restart the security mode and run kv_viptray.exe. After a while, it will be automatically disabled.
Later, we can see that viptray.exe is still unavailable. If there are still, manually delete the following files:
C: WINNTsystem32VIPTray.exe
C: WINNTsystem32WinDefendor. dll
C: WINNTsystem32friendly.exe
Virus analysis:
VipTray.exe starts from htt: // ulink4.dudu.com/setup/iebar.exe (Note: Do not download it !)
Download an iebar.exe file and ask the user to install it. The webshell is bound to the webshell. After iebar.exe is installed, the Registry is modified:
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWinlogon
Modify the key value system to C: WINNTsystem32friendly.exe ZNKwcxv =
Create BHO
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorer
Browser Helper Objects
DLL name: WinDefendor. dll
VipTray is also registered as a system service.
Service Description:
Provides Internet explorer-based network content. If this service is terminated, these features and content will be lost. If this service is disabled, other network content dependent on this service will not run properly.