Author Topic: Some general characteristics of BHO-KD infections...  (Read 1823 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34051
  • malware fighter
Some general characteristics of BHO-KD infections...
« on: January 30, 2008, 12:02:44 AM »
Hi malware fighters,

We have experienced a lot of this Trojan lately in the virus and worms, is a real Trojan horse that often installs malicious tool bars using browser security back doors. But some programs (IeDefender, Files Secure) displays Trojan.win32.BHO.aqz fake detection message as their scan\detection result. Trojan.win32.BHO.aqz may be also distributed by a new bogus codec.

Trojan.win32.BHO manual removal instructions:
Remove Trojan.win32.BHO.aqz registry values:
670ADC7B-89DC-4F88-98CC-2E3B
CF85F140
7E24E909-FB8A-4837-9DF7-05E7587CB26C
c4545fc9-26d0-4ccf-b4fb-728aed895dbd
E856E05E-1B91-4339-9EFC-9A3308CB5491
B3E45A9B-7756-46A2-AB14-90175CD374F9
BBB05D9E-0297-404D-A6BF-D8F2876B84A6
F9EAAA11-DF98-4615-A2C7-7D03C86A6BE9
69B98C68-D2B8-4A4E-9CB7-E85B6F3A7014
A8565FBC-8D53-4D4F-9BB0-CBC68A22B126
43BA0532-0D69-458A-8C71-AD0F6AE70D19
62EA9201-8CC7-4199-AC30-7744F836322E
b166be07-30a4-4d38-b781-44528a630706
D17CFF74-A19C-4C36-821A-E074E4F889CA
202EBB90-ABD4-46CC-BB5A-4F0ECC67B331
15EB9F40-D775-4463-B75B-8687B3C66BB7
6D64B03B-3B93-4AF2-BFC6-01264A4C7F2A
6A719349-BDF5-4268-9019-4ACA0C2562D2

Unregister and remove Trojan.win32.BHO.aqz dll's:
mscfg32.dll
windivx.dll
websrc32.dll
mlljh.dll
cjvy.dll
gqagksr.dll
esent9.dll
ttvbonvgl.dll
ssqppol.dll
pmspl.dll
urqnomm.dll
msvideo.dll
ecxwp.dll
stream32a.dll
vtssp.dll

Important in preventing infection is to update your Sun Java version to the most recent and
dlete previous versions

polonus
« Last Edit: January 30, 2008, 12:04:32 AM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!