Home Page Add Favorite
 
Login To Site
Username :  
Password :  
   
   
Register
Forgot my password?
Pakistan Software Library » Security » Trojan » Trojan-Dropper.Win32.Agent.albv
Main Menu
Home Page Site Stats
Add News Register
Last Comments New Articles
RSS 2.0 Contact Us
 
Support
Advanced Search
All the latest news
Category
Script Gen:0.00531s.
Site Info
Site Statistics
Top Author:
  1    admin 176
  2    Horlock 24
  3    autodilleryga 5


Membership:
  Total : 16   ( +0 )
  This month : 16
  This hour : 0
  Banned : 1


Articles:
  Total : 205  ( +5 )
  This Month : 205
  This hour : 0
  Awaiting validation : 8


Comments:
  Total : 0  ( +0 )
  This month : 0
  This hour : 0

Poll
Tracker

eXTReMe Tracker

Arshive
July 2010 (197)
Change Skin
 
 
 

Security » Trojan : Trojan-Dropper.Win32.Agent.albv
 

Trojan-Dropper.Win32.Agent.albv

Detected Mar 29 2009 16:03 GMT
Released Mar 29 2009 19:47 GMT
Published Apr 15 2009 07:34 GMT

Technical Details
Payload
Removal instructions

Technical Details

This Trojan has a malicious payload. It is a Windows PE EXE file. It is 23552 bytes in size.

Installation

The Trojan copies its executable file as follows:

%WinDir%\system\svhost.exe

In order to ensure that the Trojan is launched automatically when the system is rebooted, the Trojan adds a link to its executable file in the system registry:

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WSVCHO" = "%WinDir%\system\svhost.exe"



Payload

The Trojan adds its executable file to the Windows firewall list of trusted applications. It then launches the “iexplore.exe” process and injects its code into this process.

It also attempts to terminate the following processes:

avesvc.exe
ashdisp.exe
avgrsx.exe
bdss.exe
spider.exe
avp.exe
nod32krn.exe
cclaw.exe
dvpapi.exe
ewidoctrl.exe
mcshield.exe
pavfires.exe
almon.exe
ccapp.exe
pccntmon.exe
fssm32.exe
issvc.exe
vsmon.exe
cpf.exe
ca.exe
tnbutil.exe
avp.exe
mpfservice.exe
npfmsg.exe
outpost.exe
tpsrv.exe
pavfires.exe
kpf4ss.exe
persfw.exe
vsserv.exe
smc.exe

It also attempts to disable the following services associated with antivirus and firewall programs:

AntiVir
Avast Antivirus
AVG Antivirus
BitDefender
Dr.Web
Kaspersky Antivirus
Nod32
Norman
Authentium Antivirus
Ewido Security Suite
McAfee VirusScan
Panda Antivirus/Firewall
Sophos
Symantec/Norton
PC-cillin Antivirus
F-Secure
Norton Personal Firewall
ZoneAlarm
Comodo Firewall
eTrust EZ Firewall
F-Secure Internet Security
Kaspersky Antihacker
McAfee Personal Firewall
Norman Personal Firewall
Outpost Personal Firewall
Panda Internet Seciruty Suite
Panda Anti-Virus/Firewall
Kerio Personal Firewall
Tiny Personal Firewall
BitDefender / Bull Guard Antivirus
Sygate Personal Firewall

The Trojan also harvests passwords to web sites saved to the cache of the browsers shown below:

Mozilla FireFox
Internet Explorer

It also harvests passwords and account data for the following IM clients:

Trillian
Miranda
Yahoo Messenger
MySpace IM
Gaim

The Trojan has a built-in keylogger and can make screenshots of the user’s desktop. These screenshots are saved to the Temporary directory as <N> with <N> being a decimal number.

Harvested data is sent to the malicious user’s server:

212.158.160.***

Propagation via removable media

The Trojan copies its executable file to the root of each removable drive under the following name:

<X>:\wlan.exe, with X being the disk

In addition to its executable file, the Trojan also places the file shown below in the root directory of every disk:

<X>:\autorun.inf

This file will launch the Trojan executable file each time the user opens an infected disk using Explorer.


Removal instructions

If your computer does not have an up-to-date antivirus, or does not have an antivirus solution at all, follow the instructions below to delete the malicious program:

  1. Use Task Manager to terminate the malicious program’s process.
  2. Delete the original Trojan file (the location will depend on how the program originally penetrated the victim machine).
  3. Delete the following system registry key parameter:
    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "WSVCHO" = "%WinDir%\system\svhost.exe"
  4. Delete the following file:
    %WinDir%\system\svhost.exe
  5. Empty the temporary directory (%Temp%).
  6. Delete the files shown below from all removable storage media:
    <X>:\autorun.inf
    <X>:\wlan.exe,
    with X being the disk




Tag :  Trojan
 
 
 
 
   
 
 (Votes #: 0)
Comments (0)  Print Version
 
 
Add comments
   
 

 
 
Calendar    
«    July 2010    »
MoTuWeThFrSaSu
 
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
 
   Tag Cloud  
Aero, Author, Beta, Boot, Build, Change, Client, collections, Converter, Disable, Disk, Easy, Fighter, File, files, Free, from, Make, Manage, McAfee, Messenger, Mode, Online, other, Patch, Portable, Speed, Step, SuperDAT, System, Taskbar, Time, Unwanted, Update, Video, virus, Vista, Windows, with, your

Show all tags
   Last News  
» Unique wallpapers from Europe. Part 270
» Unique wallpapers from Europe. Part 268
» Yahoo! Messenger 10 offline installer
» Download Yahoo Messenger 9 Full Setup
» Portable RightNote 1.7.5
» DVD slideshow GUI 0.9.3.8
» Mobile Atlas Creator (formerly TrekBuddy Atlas Creator) 1.8 Alpha 15 / 1.7
» Mission X 1.2
» La Tale Online Client 5.1
» Cross Fire Client 1049
» Priston Tale 2 Client 2.0.0
» SGIs Video Converter GUI v0.3.6
» Full Video Converter 6.0.5.18
» Total Video Converter 3.61
» DISK BOOT FAILURE, INSERT SYSTEM DISK AND PRESS ENTER
» Mozilla Firefox Portable 3.6
» Install Windows XP Step By Step
» LinkSys Router Setup
» Restoring Safe Mode with a .REG file
» Recover Your Windows Xp Password
   Top News  
» Migrate XP to Windows 7 with Easy Transfer and a USB Drive
» Shin Megami Tensei: Imagine Patch 1.283U to 1.284U
» Talking Clipboard 2.9.0.0
» Advanced ETL Processor 3.1.0.8
» Trojan-Dropper.Win32.Agent.albv
» Children and the Internet
» 2005
» Who creates malware and why?
» 2004
» What if my computer is infected?
» DISK BOOT FAILURE, INSERT SYSTEM DISK AND PRESS ENTER
» Unique wallpapers from Europe. Part 213
» 1998
» 1988
» Backdoor.Win32.Clampi.a
» Unique wallpapers from Europe. Part 211
» 2003
» 1993,1994
» 1989
» History of malicious programs
   Random News  
» Unique wallpapers from Europe. Part 238
» TRIM CommandsTRIM
» SunlitGreen PhotoEdit Portable 1.3.0 Build 421
» Installing RAM Disk
» 1997
» Disable Unwanted Startup Programs
» Access Frequently Used Items in Windows 7 with Jump Lists
» Visual Importer Enterprise 7.7.5.11
» Unique wallpapers from Europe. Part 254
» Priston Tale 2 Client 2.0.0
» Wonderland Online Client 6.0.0.2010707
» Blue sreen error 0000007
» Unique wallpapers from Europe. Part 228
» Moo0 ImageViewer 1.67
» Error loading C:\PROGRA~1\MYWEBS~\bar\2.bin\MWSBAR.DLL
» Second Life Client 2.0.1.20730
» DVD Author Plus 2.15
» Shin Megami Tensei: Imagine Patch 1.283U to 1.284U
» How To Manage UAC Notifications in Windows 7
» Restoring Safe Mode with a .REG file