filename:dream.exe\sbl.exe
file size:146592 bytes
AV:(Kaspersky 7.0)Trojan.Win32.Delf.adf
MD5:bb2da6dcb865b70fe0754db71cee72d8
Sbl.exe has been seen to perform the following behavior(s):
Executes a Process
%Systemroot%\system32\1.inf
%Systemroot%\system32\dream.exe
%Systemroot%\system32\plmmsbl.dll
download spyware to your computers:
%Systemroot%\system32\gmxe.dll
%Systemroot%\system32\drivers\swmcswozyn.sys
%Systemroot%\system32\drivers\xpg7.sys
C:\Favorites\**.url
Added as a Registry auto start to load Program on Boot up
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
dream = REG_SZ, C:\winnt\system32\dream.exe
melove = REG_SZ, C:\winnt\system32\dream.exe
the two path direct C:\winnt\system32\dream.exe
If your computer system is windows xp ,this path direct to c:\windows\system32\dream.exe
Writes to another disk
Autorun.inf and sbl.exe.
net stop your firewall
try to stop process
avp.exe
EXESPY WXR95 REGMON FILE MONITOR REGMONEX WINDOW DETECTIVE DEBUGVIEW RESSPY ADVANCED REGISTRY TRACER REGSNAP MEMSPY MEMORY DOCTOR PROCDUMP32 MEMORY EDITOR FROGSICE SMU WINSPECTOR MEMORY DUMPER MEMORYMONITOR NUMEGA SOFTICE LOADER URSOFT W32DASM -=CHINA CRACKING GROUP=- OllyDbg TRW2000 DEFAULT IME NDOW- 360 [MAXTHON]
how to remove sbl.exe
chose netlink use Mandatory deleted software
del C:\windows\system32\1.inf
C:\windows\system32\dream.exe
C:\windows\system32\plmmsbl.dll
C:\autorun.inf
C:\sbl.exe
D:\autorun.inf
D:\sbl.exeE:\autorun.inf
E:\sbl.exeF:\autorun.inf
F:\sbl.exe
check regedit and del this:
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
[xpg7 / xpg7][Stopped/Auto Start]<\??\C:\winnt\system32\drivers\xpg7.sys>
if you have ant question please mail to me ....
