Manually scan smss.exe hook. dll foxkb. sys

Source: Internet
Author: User

Virus name: Trojan-PSW.Win32.OnLineGames.qw [DLL] (Kaspersky), rootkit. win32.agent. FY [sys] (Kaspersky)
Virus alias: Trojan. psw. win32.jhonline. A [EXE] (rising), Trojan. psw. win32.onlinegames. DBA [DLL] (rising)
Trojan. psw. win32.jhonline. A [sys] (rising)
Virus size: 49,664 bytes
Shelling method:
Sample MD5: 335838f3badbc6532211e19988f008a9
Sample sha1: 1c13b0d60b8838dcb5581e21f0526b1d6412a5d8
Time detected: 2007.7
Time updated: 2007.7
Associated Virus:
Transmission Mode: Spread through malicious websites and download other Trojans

Technical Analysis
============

After the trojan is run, copy it to the system directory:
% WINDOWS % \ System \ smss.exe
And release the DLL:
% WINDOWS % \ System \ hook. dll

Release the driver foxkb. sys at the current location:

[HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Services \ foxkb]

The trojan hides its own processes and manages them in the task manager, procexp, and other processes.ProgramIs invisible.

Create a startup Item:

[HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run]
"Qqrest" = "% WINDOWS % \ System \ smss.exe"

Rewrite every 5 seconds.

Clear steps
============

1. Use icesword to end the Trojan process:
% WINDOWS % \ System \ smss.exe

2. delete the file (if you are prompted that the file cannot be deleted, download the file Trojan force deletetool from down.45it.com to force delete the file ):
% WINDOWS % \ System \ smss.exe
% WINDOWS % \ System \ hook. dll

3. Delete the trojan startup Item (detailed steps: Open Sreng-startup project-Registry): The Sreng software can also be downloaded at down.45it.com.

[HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run]
"Qqrest" = "% WINDOWS % \ System \ smss.exe"

4. Delete the driver information added by the Trojan horse in the Registry (detailed steps: Open Sreng-Start Project-driver ):
[HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Services \ foxkb]

5. Delete the driver file released by the trojan. (If you are prompted that the file cannot be deleted, go to down.45it.com to download the file for force deletion ):
Foxkb. sys

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.