Symptoms
Presence of package.exe in "c:\Documents and Settings\All Users\Start Menu\Programs\Startup", "%windir%\All Users\Main menu\Programs\StartUp" and "%system32%" folders and in processes list.
Presence in start-up registry key "HKLM\Software\Microsoft\Windows\CurrentVersion\Run" of the string "sassfix" pointing to "%system32%\packer.exe".
Removal instructions:
Manual removal:
* open Task Manager by pressing [CTR]+[ALT]+[DEL] or [CTRL]+[SHIFT]+[ESCAPE] for Win2000/XP
* use End Process in Processes tab on package.exe
* open Registry Editor typing [WIN]+[R]regedit[ENTER]
* remove the HKLM\Software\Microsoft\Windows\CurrentVersion\Run\sassfix registry key
* delete the enumerated files in the symptoms section
Automatic removal: let BitDefender disinfect infected files
Analyzed By
Mircea Ciubotariu BitDefender Virus Researcher
SHARE
THIS ON