Virus name: Trojan-PSW.Win32.OnLineGames.qw [DLL] (Kaspersky), rootkit. win32.agent. FY [sys] (Kaspersky)
Virus alias: Trojan. psw. win32.jhonline. A [EXE] (rising), Trojan. psw. win32.onlinegames. DBA [DLL] (rising)
Trojan. psw. win32.jhonline. A [sys] (rising)
Virus size: 49,664 bytes
Shelling method:
Sample MD5: 335838f3badbc6532211e19988f008a9
Sample sha1: 1c13b0d60b8838dcb5581e21f0526b1d6412a5d8
Time detected: 2007.7
Time updated: 2007.7
Associated Virus:
Transmission Mode: Spread through malicious websites and download other Trojans
Technical Analysis
============
After the trojan is run, copy it to the system directory:
% WINDOWS % \ System \ smss.exe
And release the DLL:
% WINDOWS % \ System \ hook. dll
Release the driver foxkb. sys at the current location:
[HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Services \ foxkb]
The trojan hides its own processes and manages them in the task manager, procexp, and other processes.ProgramIs invisible.
Create a startup Item:
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run]
"Qqrest" = "% WINDOWS % \ System \ smss.exe"
Rewrite every 5 seconds.
Clear steps
============
1. Use icesword to end the Trojan process:
% WINDOWS % \ System \ smss.exe
2. delete the file (if you are prompted that the file cannot be deleted, download the file Trojan force deletetool from down.45it.com to force delete the file ):
% WINDOWS % \ System \ smss.exe
% WINDOWS % \ System \ hook. dll
3. Delete the trojan startup Item (detailed steps: Open Sreng-startup project-Registry): The Sreng software can also be downloaded at down.45it.com.
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run]
"Qqrest" = "% WINDOWS % \ System \ smss.exe"
4. Delete the driver information added by the Trojan horse in the Registry (detailed steps: Open Sreng-Start Project-driver ):
[HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Services \ foxkb]
5. Delete the driver file released by the trojan. (If you are prompted that the file cannot be deleted, go to down.45it.com to download the file for force deletion ):
Foxkb. sys