Sunday, January 18, 2009

Burgspill Trojan

Removing Burgspill
Categories: Trojan
This loose category includes a variety of Trojans that damage victim machines or
threaten data integrity, or impair the functioning of the victim machine.

Multi-purpose Trojans are also included in this group, as some virus writers
create multi-functional Trojans rather than Trojan packs.

Burgspill Also known as:

[Kaspersky]Trojan-Downloader.Win32.Delf.djg,Trojan-Downloader.Win32.Zlob.fee,Trojan-Downloader.Win32.Delf.djl,Trojan-Downloader.Win32.Delf.dke,Trojan-Downloader.Win32.Delf.dkk;
[McAfee]Generic Downloader.c;
[F-Prot]W32/NewMalware-LSU-based!Maximus;
[Other]Mal/DelpDldr-E,Trojan-Downloader.Win32.Delf.cwv,Trojan:Win32/Delflob.I

Visible Symptoms:
Files in system folders:
[%WINDOWS%]\oggview32.dll
[%WINDOWS%]\pmspl.dll
[%WINDOWS%]\windivx.dll
[%WINDOWS%]\oggview32.dll
[%WINDOWS%]\pmspl.dll
[%WINDOWS%]\windivx.dll

How to detect Burgspill:

Files:
[%WINDOWS%]\oggview32.dll
[%WINDOWS%]\pmspl.dll
[%WINDOWS%]\windivx.dll
[%WINDOWS%]\oggview32.dll
[%WINDOWS%]\pmspl.dll
[%WINDOWS%]\windivx.dll

Registry Keys:
HKEY_CURRENT_USER\software\microsoft\clock2
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\ext\stats\{819efd78-6fd4-42ef-9030-f6dab24bb9f0}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{819efd78-6fd4-42ef-9030-f6dab24bb9f0}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{ff5137b5-c506-4d9b-8682-e0be4675b899}

Registry Values:
HKEY_CURRENT_USER\software\microsoft\bind
HKEY_CURRENT_USER\software\microsoft\bind

Removing Burgspill:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:
Remove ad20.net Tracking Cookie
QZap1 Trojan Removal instruction

No comments: