| Name |
%SysDir%\dx32cxlp.exe |
Description
|
Trojan Nemog. To autostart uses the Registry Run keys and the services keys: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\dx32cxel HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_DX32CXEL Creates the system service called "dx32cxel". Hides its service and files by hooking several APIs and returning null results for any API calls. Creates backdoor using ports 4661, 4242, 8080, 4646, 6565, and 3306. Receives commands from a remote attacker through a backdoor to perform the following actions: 1) Uninstall itself 2) Update itself 3) Download a file Overwrites the %System%\DRIVERS\ETC\HOSTS file with the text, which prevents access to certain security-related Web sites. Removal: Go to HKLM\SOFTWARE\Microsoft\Internet Explorer Delete the values: "mutexname" = "mSRMHED" "vers" = "0x10050" Delete the keys: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\dx32cxel HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_DX32CXEL Restore "hosts" file. Restart your computer. |
|