What happened to the Messenger Plus! forums on msghelp.net?
Shoutbox » MsgHelp Archive » Skype & Technology » Tech Talk » Are These Genuine System Files?

Are These Genuine System Files?
Author: Message:
M73A
Veteran Member
*****

Avatar


Posts: 3213
Reputation: 37
34 / Male / Flag
Joined: Jul 2004
O.P. RE: Are These Genuine System Files?
shredding time:P

found this
quote:
Originally posted by sophos website


This section is for technical experts who want to know more.

Troj/Bdoor-YP is a Trojan for the Windows platform.

When first run Troj/Bdoor-YP copies itself to <System>\vssms32.exe and
creates the following files:

<Windows>\hkr32.asm
<System>\ldapi32.exe
<System>\ntcvx32.dll
<System>\ntswrl32.dll

The following registry entry is created to run vssms32.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
vssms32
<System>\vssms32.exe

The following registry entries are set, affecting internet security:

HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\
FirewallPolicy\StandardProfile\AuthorizedApplications\List\
<Windows>\System32
vssms32.exe
<System>\vssms32.exe:*:Enabled:Dnode

Registry entries are created under:

HKCU\Software\

Troj/Bdoor-YP also attempts to install the Trojans Troj/Mpass-B and
Troj/LdPinch-IP.



[Image: lost7ru.gif]
08-22-2007 11:21 AM
Profile E-Mail PM Find Quote Report
« Next Oldest Return to Top Next Newest »

Messages In This Thread
Are These Genuine System Files? - by M73A on 08-22-2007 at 11:05 AM
RE: Are These Genuine System Files? - by andrewdodd13 on 08-22-2007 at 11:13 AM
RE: Are These Genuine System Files? - by M73A on 08-22-2007 at 11:21 AM
RE: Are These Genuine System Files? - by Pyro on 08-25-2007 at 04:40 AM
RE: Are These Genuine System Files? - by M73A on 08-25-2007 at 09:40 AM


Threaded Mode | Linear Mode
View a Printable Version
Send this Thread to a Friend
Subscribe | Add to Favorites
Rate This Thread:

Forum Jump:

Forum Rules:
You cannot post new threads
You cannot post replies
You cannot post attachments
You can edit your posts
HTML is Off
myCode is On
Smilies are On
[img] Code is On