SoftwareTipsandTricks.com
Home Forums Windows 7 Security Tips
Forums

Windows 7
Windows Vista
Windows XP

Security Tips
Troubleshooting
Keyboard Shortcuts
Encyclopedia


Drivers

Internet Terms
Computer Terms

File Extensions (75)
File Extensions (15K+)

Startup Applications
Necessary Files
Useless Files
At Your Option Files
Dangerous Files
Browser Objects

DLL Files
SYS Files
INF Files
OCX Files
VXD Files

Virus Database
Virus Warnings

Easter Eggs
Tips and Tricks
Articles
Hot Downloads


Privacy Policy
Contact Us







  msinfo.exe

Name msinfo.exe

Description

Backdoor.IRC.Aladinz.M is a backdoor Trojan horse that uses malicious scripts in the mIRC client software, allowing unauthorized remote access.

When it is executed, it performs the following actions:
Creates different files in %System32%\Wbem\Mof\Good\System:
@ - clean text log file
conn.dll - clean IRC dll file
csrss.dll - malicious IRC script detected as IRC Trojan
and others.

Attempts to copy itself as the following files:
C:\wupd.exe
%System32%\msinfo.exe

Adds the value:
"MSInfo" = "msinfo.exe"
"MSUpdate"="wupd.exe"
to the registry keys:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
and "MSInfo" = "msinfo.exe" to
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices

Disables DCOM support by setting the value to:
"EnableDCOM" = "N"
in the registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\OLE\EnableDCOM

Allows a remote attacker to control the computer. The functions provided include:

Retrieving information about the computer.
Stopping and restarting the Trojan.
Downloading and running files.
Scanning hosts for vulnerabilities using the Remacc.Dwremote.

EnabledDCOM value to "Y." in the system registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\OLE\EnableDCOM

And use antivirus (also check How To Remove section)Startup Optimizer to remove it from startup.


Still have a problem? Ask for help at our discussion forum.



Search Dangerous Files :
 

: : Recent posts at Forums : :

pvsmrroecq

ehneolkjqi

wfznwzgdkj

aahkpxuedk

Nike Air Max

maxgabnyxt

Тонировка бал

Experimental Poke out

owzroiouut

cvaltjdxpc

jhuxdvwkjv

cfzoielcxv

zwcxootfbl

oejzbushsx

Олимп трейд

zlkqvwigxe

cpmvwqniwj

nipngyiuqp

mhtxjhdfgf

viixplbfsf

hmahtdvxtf

Sexual pictures

fqgmkufqrf

rlasqmzoyj

mmujrxvgnb

Олимп трейд

spjynrrzoq

Pictures from social networks

Pictures from social networks

Loose galleries




SoftwareTipsandTricks, All Rights Reserved.