Wednesday, December 10, 2008

Higlieder Trojan

Removing Higlieder
Categories: Trojan
This category includes a variety of Trojans that damage victim machines or
threaten data integrity, or impair the functioning of the victim machine.

Higlieder Also known as:

[Kaspersky]Email-Worm.Win32.Bagle.hc,Email-Worm.Win32.Bagle.hg,Trojan-Downloader.Win32.Bagle.cw;
[Other]Win32/Higlieder,Win32/Higlieder.E,Win32/Higlieder.M,Bloodhound.Beagle,Win32/Higlieder.O,Win32/Higlieder.AJ

Visible Symptoms:
Files in system folders:
[%APPDATA%]\hidires\hidr.exe
[%APPDATA%]\hidires\m_hook.sys
[%PROFILE_TEMP%]\~1.exe
[%PROFILE_TEMP%]\~6.exe
[%PROFILE_TEMP%]\~??.ee
[%PROFILE_TEMP%]\~???.ee
[%APPDATA%]\hidires\hidr.exe
[%APPDATA%]\hidires\m_hook.sys
[%PROFILE_TEMP%]\~1.exe
[%PROFILE_TEMP%]\~6.exe
[%PROFILE_TEMP%]\~??.ee
[%PROFILE_TEMP%]\~???.ee

How to detect Higlieder:

Files:
[%APPDATA%]\hidires\hidr.exe
[%APPDATA%]\hidires\m_hook.sys
[%PROFILE_TEMP%]\~1.exe
[%PROFILE_TEMP%]\~6.exe
[%PROFILE_TEMP%]\~??.ee
[%PROFILE_TEMP%]\~???.ee
[%APPDATA%]\hidires\hidr.exe
[%APPDATA%]\hidires\m_hook.sys
[%PROFILE_TEMP%]\~1.exe
[%PROFILE_TEMP%]\~6.exe
[%PROFILE_TEMP%]\~??.ee
[%PROFILE_TEMP%]\~???.ee

Registry Keys:
HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_m_hook
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\m_hook

Registry Values:
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run

Removing Higlieder:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:
DOS32.QHA Trojan Removal instruction
Iani Backdoor Cleaner
Slodist Trojan Cleaner
Removing RemoteNC RAT

No comments: