Mdelk.exe 包括了 trojan.mitglieder.gb 和 troj_mitglied.aa 木马。
命令行删不掉。
MDELK.EXEAUTOMATED MALWARE PROFILE, ANALYSIS, REMOVAL AND SIGNATURE INFORMATION:
DEFINITION OF: MDELK.EXE
Safety Rating: Known Malware, do not run
Malware Family: Part of Malware group - Trojan MitGlieder GB
Determination: Automatically determined using Prevx centralized heuristics
Malware Form: TROJAN
Protection: Prevx provides powerful security products that you can use to detect, remove and protect you from MDELK.EXE and safeguard your PC against viruses, trojans, worms, spyware, rootkits and adware
Why risk having spyware on your PC when it takes less than 2 minutes to thoroughly check it with Prevx CSI? And it is totally free. Click here to check your PC with Prevx CSI Now.
First seen: May 28 2006 (GMT)
Last seen: May 28 2006 (GMT)
File Size: 36,826 bytes
MALWARE ASSESSMENT: PREVX 4 AXES OF EVIL METHODOLOGY1. COVERT ANALYSIS OF: MDELK.EXE
File Names Used: 192
Paths Used: 43
Common File Name: MDELK.EXE
Common Path: %appdata%\m\
Vendor Information: No Vendor details specified
MDELK.EXE may use 192 or more path and file names, these are the most common:
1 :%desktop%\malware on stubbs laptop (stubbs101)\06DE0C25DA69D9718FAD0018DDC7.....EXE
2 :%profiles%\alex\impostazioni locali\temp\~2.EXE
3 :%TEMP%\~12.EXE
4 :%TEMP%\~23C6.EXE
5 :%TEMP%\~23C7.EXE
6 :%TEMP%\~23D1.EXE
7 :%TEMP%\~23D3.EXE
8 :%TEMP%\~23D5.EXE
9 :%TEMP%\~23D7.EXE
10:%TEMP%\~23D9.EXE
11:%TEMP%\~2414.EXE
12:%TEMP%\~241A.EXE
13:%TEMP%\~CE3.EXE
14:?:\A00000000
File Name Structure: Normal
File and Path Structure: Suspicious, code execution from unusual
location<br>2. RELATIONSHIP ANALYSIS OF: MDELK.EXE
Malicious
Objects Created: 19
objects
Malicious Creators: 2
Malware Run Keys: Creates registry run keys for known malware
objects
Self Persists: Yes, creates copies of itself
Antivirus Detection: No third party antivirus detection observed
Anti-Spyware Detection: No third party anti-spyware detection observed
3. ACTIVITY ANALYSIS OF: MDELK.EXE
The following behaviors have been observed for this
object:
Installs programs.
Deletes programs.
Invokes dll components.
Creates Run Keys.
Runs other programs.
Communicates with web sites using httpout protocols.
Communicates with other computers across the web.
Has outbound communications.
Creates registry entries.
Creates run keys for known malware.
Creates known malware.
Creates copies of itself.
4. PROPAGATION ANALYSIS OF: MDELK.EXE
Malware Group Propagation Rate: Moderate (spreading)
Malware Group: Trojan MitGlieder GB
Copyright Prevx Limited 2005, 2006
[用户系统信息]Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; GreenBrowser)