Main Behavior:
1. Release files:
C: \ windows \ system32 \ scvvhsot.exe
671,744 bytes
C: \ windows \ Tasks \ at1.job
346 bytes
2. Add a startup Item:
HKEY_CURRENT_USER \ Software \ Microsoft \ Windows \ CurrentVersion \ Run
Key name: Yahoo messengger, pointing to scvvhsot.exe.
3. Modify the registry and start it with Explorer:
HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows NT \ CurrentVersion \ Winlogon
Shell = "assumer.exe scvvhsot.exe"
4. Disable registry and task manager:
HKEY_CURRENT_USER \ Software \ Microsoft \ Windows \ CurrentVersion \ Policies \ System
Disabletaskmgr = 0x00000001
Disableregistrytools = 0x00000001
5. connect to the network and download things in disorder (not implemented ):
Hxxp: // nhatquanglan2.0catch.com/setting.nql
Hxxp: // nhatquanglan2.0catch.com/setting.xls
Hxxp: // www.freewebs.com/nhattruongquang/setting.nql
Hxxp: // www.freewebs.com/nhattruongquang/setting.xls
6. Add a scheduled task:
C: \ windows \ Tasks \ at1.job
346 bytes ~~
Solution:
1. Download Sreng. And then disconnect the network.
2. When Sreng is enabled, it will prompt
HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows NT \ CurrentVersion \ Winlogon
The item is maliciously modified. The item is automatically fixed after being clicked.
3. Deleting Yahoo messenggerrefers to scvvhsot.exe (step 1: Open Sreng-Start Project-registry )).
4. restart the computer and delete the file:
C: \ windows \ system32 \ scvvhsot.exe
C: \ windows \ Tasks \ at1.job