Virus name: Trojan-PSW.Win32.OnLineGames.zl (Kaspersky)
Virus alias: Trojan. PSW. win32.OnlineGames. cql (rising), Trojan. PSW. win32.SunOnline. f [dll] (rising) Win32.Troj. PSWGameT. lk.17408, Win32.Troj. PSWGameT. xk.17408 [dll] (drug overlord)
Virus size: 22,528 bytes
Shelling method:
Sample MD5: 7f14320161a8e7530c719965a6b8adbd
Sample SHA1: a4d7132acbdee2e7765a6d7c34e1559c8cc1ca
Time detected: 2007.6
Last Updated: 2007.6.27
Associated Virus:
Transmission methods: malicious webpage and other virus downloads
Technical Analysis
After the trojan is run, copy itself to the system directory:
% Windows % \ Kvsc3.exe
Release dll injection process:
% System % \ Kvsc3.dll
(Note: If Kvsc3.dll already exists, the dll released by the trojan uses a random letter as the file name, such as olnryh. dll and ojprzc. dll)
Startup items created for Trojans:
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run]
"Kvsc3" = "% Windows % \ Kvsc3.exe"
Clear steps
1. Delete the trojan startup Item:
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run]
"Kvsc3" = "% Windows % \ Kvsc3.exe"
2. restart the computer
3. Delete the trojan file:
% Windows % \ Kvsc3.exe
% System % \ Kvsc3.dll