Bienvenido! - Willkommen! - Welcome!

Bitácora Técnica de Tux&Cía., Santa Cruz de la Sierra, BO
Bitácora Central: Tux&Cía.
Bitácora de Información Avanzada: Tux&Cía.-Información
May the source be with you!

Sunday, November 16, 2008

Troj/Agent-GTN or TR/Crypt.XPACK.Gen

Source
Please follow the instructions for removing Trojans.
More Information

Troj/Agent-GTN is a Trojan for the Windows platform.
When Troj/Agent-GTN is installed the following files are created:
%System%\hrpdcf.bin (harmless data file, can be deleted)
%System%\mp3res.dll (detected as Troj/Agent-GTN)
%System%\xprot.sys (detected as Troj/Agent-GTN)
The following registry entries are created to run code exported by mp3res.dll on startup:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\mp3res
DllName
mp3res.dll0
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\mp3res
Startup
mp3res
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\mp3res

No comments: