









 |
W32/Reyds.A Virus
| Name |
W32/Reyds.A Virus |
| Aliases |
W32.Reyds.A, Troj/Delf-DZX, PE_REYDS.A-O |
| Discovered on |
February 21, 2007 |
Virus Information - W32/Reyds.A Virus:
W32/Reyds.A is a virus. The virus will infect Windows systems and attempts to download files from the Internet.
Upon execution, the virus copies itself as death.exe and supervise.exe in the Windows System folder.
The virus searches for the .exe files in all network drives and adds its code to the beginning of the data of the host files.
The virus component supervise.exe drops death.Sishen file in the Windows System folder which is a non-malicious file.
The virus modifies the registry at following locations:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL
The virus also attempts to download the following files:
http://newasp.com.cn/test/
http://newasp.com.cn/test/2.exe
http://newasp.com.cn/test/3.exe
http://newasp.com.cn/test/4.exe
The virus tries to terminate some of the security related processes.
The virus also closes windows whose window name is any of the following:
KV2006
Duba
IceSword
RavMon.exe
RavMon.exe
RavMonClass
Symantec AntiVirus
Symantec AntiVirus
Tapplication
TfLockDownMain
VirusScan
Wrapped gift Killer
ZAFrameWnd
ZoneAlarm
pjf(ustc)

|