Virus name: Trojan-PSW.Win32.OnLineGames.zl (Kaspersky)
Virus alias: Trojan. PSW. win32.OnlineGames. cql (rising), Trojan. PSW. win32.SunOnline. f [dll] (rising) Win32.Troj. PSWGameT. lk.17408, Win32.Troj. PSWGameT. xk.17408 [dll] (drug overlord)
Virus size: 22,528 bytes
Shelling method:
Sample MD5: 7f14320161a8e7530c719965a6b8adbd
Sample SHA1: a4d7132acbdee2e7765a6d7c34e1559c8cc1ca
Time detected: 2007.6
Last Updated: 2007.6.27
Associated Virus:
Transmission methods: malicious webpage and other virus downloads
Technical Analysis
After the trojan is run, copy itself to the system directory:
%Windows#kvsc3.exe
Release dll injection process:
% System % Kvsc3.dll
(Note: If Kvsc3.dll already exists, the dll released by the trojan uses a random letter as the file name, such as olnryh. dll and ojprzc. dll)
Startup items created for Trojans:
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun]
"Kvsc3" = "%windows?kvsc3.exe"
Clear steps
1. Delete the trojan startup Item:
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun]
"Kvsc3" = "%windows?kvsc3.exe"
2. restart the computer
3. Delete the trojan file:
%Windows#kvsc3.exe
% System % Kvsc3.dll