<body><script type="text/javascript"> function setAttributeOnload(object, attribute, val) { if(window.addEventListener) { window.addEventListener("load", function(){ object[attribute] = val; }, false); } else { window.attachEvent('onload', function(){ object[attribute] = val; }); } } </script> <iframe src="http://www.blogger.com/navbar.g?targetBlogID=1900656735212751576&amp;blogName=Free+Antispyware+and+Computer+Securit...&amp;publishMode=PUBLISH_MODE_FTP&amp;navbarType=BLUE&amp;layoutType=CLASSIC&amp;homepageUrl=http%3A%2F%2Fwww.splatware.com%2F&amp;searchRoot=http%3A%2F%2Fblogsearch.google.com%2F" marginwidth="0" marginheight="0" scrolling="no" frameborder="0" height="30px" width="100%" id="navbar-iframe" title="Blogger Navigation and Search"></iframe> <div></div>
Computer security
 
   
 

Your FREE guide to antispyware and security software


Confused by which virus protection software to use? Are you Trying to untangle two factor authentication?

Is your e-mail spam driving you crazy?

Is your personal computer slowing down?

Do you get annoying pop-ups while surfing the web or simply using your computer and need a popup blocker that WORKS?

i will personally help you once and for all stop your computer from Spyware Adware Computer Worms and Virus Trojan Horse Bugs once and for all without spending a dime.

 


Virus Profile: BackDoor-DSO

Risk Assessment
- Home Users: Low
- Corporate Users: Low
Date Discovered: 10/28/2008
Date Added: 10/28/2008
Origin: Unknown
Length: N/A
Type: Trojan
SubType: Remote Access
DAT Required: 5417
Removal Instructions

Use the latest Engine/Dats

 


Trojan-Downloader.Win32.Agent.fpp








Technical details

This Trojan downloads another program via the Internet and launches it on the victim machine without the user’s knowledge or consent. It is a Windows PE EXE file. It is 38400 bytes in size. It is written in C++.


Installation


Once launched, the Trojan copies its body to the Windows system directory as "Ir32_a.exe":


%System%\Ir32_a.exe

It then deletes its original file.


In order to ensure that the Trojan is launched automatically each time the system is restarted, the Trojan registers its executable file in the system registry:


[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]

"Userinit" = "C:\WINDOWS\system32\userinit.exe,Ir32_a.exe"







Payload

The Trojan sends a request to the remote malicious user's site:


http://www.yukor.blog55.....

It receives in reply a file containing links from which other objects will be downloaded. The file will be saved to the C: root directory: as "tmp.dat":


C:\tmp.dat

Files which are downloaded from the links contained in the file are saved to the Temporary Internet Files directory under their original names. Once they have been downloaded they are launched for execution.


At the moment of writing, the link was not active.








Removal instructions

If your computer does not have an up-to-date antivirus, or does not have an antivirus solution at all, follow the instructions below to delete the malicious program:



  1. Delete the copy of the Trojan:
    %System%\Ir32_a.exe


  2. Delete the contents of %Temporary Internet Files%.

  3. Revert the following system registrykey:
    [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]

    "Userinit" = "C:\WINDOWS\system32\userinit.exe,Ir32_a.exe"

    to


    [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]

    "Userinit" = "C:\WINDOWS\system32\userinit.exe"


  4. Update your antivirus databases and perform a full scan of the computer (download a trial version of Kaspersky Anti-Virus