Trojan installer win32.trojdownloader. delf.114688 virus behavior:
This virus is a Trojan Downloading. It downloads other viruses from the Internet to the customer's machine and runs the virus. After the virus runs, a DLL file is generated to the system directory.
1. Generate a file
% Windir % \ system32 \ downdll. dll
2. Modify the Registry
HKEY_CURRENT_USER \ Software \ Microsoft \ Windows \ CurrentVersion \ Internet Settings \ connections
Keys = HEX: 3C, 06, 01, 00, 00, AF, 08, A1, C7, 01,01, 00, 00, C0, A8, 1C, F4,
HKEY_CURRENT_USER \ Software \ Microsoft \ Windows \ CurrentVersion \ ext \ stats \ {FB5F1910-F110-11D2-BB9E-00C04F795683} \ iw.e
Count = DWORD: 00000005
HKEY_CURRENT_USER \ Software \ Microsoft \ Windows \ CurrentVersion \ ext \ stats \ {FB5F1910-F110-11D2-BB9E-00C04F795683} \ iw.e
Time = HEX: D7, 07,08, 10, 19, 00, 9B, 00,
3. Create an ie e. EXE process after the virus runs.
4. Download the virus file from http: // www. *****. CN/images/JS/az.exe and save it to the C: root directory.
5. Generate a delme. BAT file under c: \ windows \ system32 to delete the source file.