Les informations contenues dans cette rubrique de notre site web sont constamment mises à jour. Afin de vous garantir un contenu le plus actualisé possible, elles sont uniquement diffusées en anglais.

Virus Profile: Generic.dx!gfb!3AEA288C07DB

Threat Search
Imprimer
   
Virus Profile information details
Risk Assessment: Home Low | Corporate Low
Date Discovered: 29/10/2009
Date Added: 29/10/2009
Origin: N/A
Length: N/A
Type: Trojan
Subtype: N/A
DAT Required: 5786
Removal Instructions
   
 
 
   

Description

This is a Trojan detection. Unlike viruses, Trojans do not self-replicate. They are spread manually, often under the premise that they are beneficial or wanted. The most common installation methods involve system or security exploitation, and unsuspecting users manually executing unknown programs. Distribution channels include email, malicious or hacked web pages, Internet Relay Chat (IRC), peer-to-peer networks, etc.

File Properties

    • File Name : dllhost.exe
    • Size         : 8,984 bytes
    • MD5         : 3AEA288C07DB42761E7BD83431FFE1D4
    • SHA1       : EBFACF13962C9AFE32DB58B6AB4849DEEDD39C4D

Aliases

    • Kaspersky : Trojan.Win32.Pincav.jbs
    • Microsoft   : Backdoor:Win32/Poison.M
    • Symantec : Backdoor.Ciadoor
    • Ikarus      : Packed.Win32.Klone

Indication of Infection

  • Existence of mentioned registry key(s)
  • Connections to the mentioned remote hosts

Methods of Infection

Trojans do not self-replicate. They are spread manually, often under the premise that the executable is something beneficial. Distribution channels include IRC, peer-to-peer networks, newsgroup postings, email, etc. Certain known variants were also known to be installed via web exploits.

   

Virus Characteristics

This is a generic detection for Trojans. Trojan behavior can be found in various malware families like "downloader", "dropper", "backdoor", "password stealer", etc. They are standalone applications that might call other malware or infect your machine on executing.

They can act in various ways to steal your data, private information, or resources.

It enables backdoor functionalities by connecting to a remote site and performing actions as programmed by a remote attacker.

The following registry is used:

  • HKEY_LOCAL_MACHINE \SOFTWARE\Microsoft\Active Setup\Installed Components\{04D76A86-B759-FCF9-9BF3-BFB1C189EAC8}
    "Stubpath" = "File Path\dllhost.exe"

The above mentioned registry activates on every reboot, and the Trojan variants register themselves.

It establish connection with the remote host 61.196.[removed] using the port 80.

The following mutex has been created:

It creates a mutex with the name "!VoqQ.I4"

   

All Users:
Use current engine and DAT files for detection and removal.

Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).

Additional Windows ME/XP removal considerations

   

Un ordinateur infecté ? Obtenez l'aide d'un expert !

McAfee
Service de suppression des virus

Contactez l'un de nos spécialistes en sécurité par téléphone. Regardez votre PC pendant que nous résolvons le problème à distance.

$89.95 (USD)

Publicité