
| Aliases | Trojan.Win32.PSWQQPass.462848 | ||
|---|---|---|---|
| Typical Symptoms | |||
| Discovered | [korea] 2009-02-25 [Foreign] 0000-00-00 |
||
| Type | Trojan Horse | ActiveField | Win32 |
| Destory/Distribution | ![]() ![]() |
||
| Origin | others | Encryption | NO |
| Location | File | Memory residence | NO |
| Scan engine needed |
2009-02-25 [Able to detect & repair]
|
||
[Symptom of Infection] 1. It creates files to below path. (Account Folder)\Local Settings\Temp\(Random Folder).TMP\server.exe (System Folder)\drivers\etc\(Random 8-digits).dll (System Folder)\XSJbAjxCyt.del (System Folder)\XSJbAjxCyt.ini 2. Infected system adds registries like below [HKLM\System\CurrentControlSet\Services\SRAT_Service] Register as Service "Description" = "SRAT·þÎñ¶Ë" "DisplayName" = "SRAT_Service" "ImagePath" = "(System Folder)\svchost.exe -k netsvcs" [HKLM\System\CurrentControlSet\Services\SRAT_Service\Parameters] "ServiceDLL" = "(System Folder)\drivers\etc\(Random 8-digits).dll" 3. It tries to access to below site. jiwc.33xx.xxx [Notation] - "(System Folder)" could be different by system, and generally this is "C:\Windows\System (Windows95/98/Me), C:\Winnt\System32 (Windows NT/2000), C:\Windows\System32 (Windows XP)". |
[How to repair] - ViRobot Desktop 5.5 : [Tools] -> [Configuration] -> [Virus Scan] : Check all files |