Computing.Net > Forums > Security and Virus > Manual Removal Downloader Trojan

Computing.Net: Over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to sign up now, it's free!

Manual Removal Downloader Trojan

Reply to Message Icon

Original Message
Name: Jennifer SUMN
Date: December 3, 2002 at 12:57:11 Pacific
Subject: Manual Removal Downloader Trojan
OS: Various
CPU/Ram: Various
Comment:

Does anyone have manual removal instructions for the Downloader Trojan? Thanks...


Report Offensive Message For Removal


Response Number 1
Name: Latika
Date: December 3, 2002 at 13:44:03 Pacific
Reply:

Report Offensive Follow Up For Removal

Response Number 2
Name: murve
Date: December 3, 2002 at 13:58:57 Pacific
Reply:

hi jennifer,
here's some info on how to delete this trojan:
the alias' for this trojan are:
Troj/Zasil-A (Sophos), Trojan.Zasil (Symantec), TrojanClicker.Win32.Zasil (AVP)

Method Of Infection:
This trojan connects to a remote website to retrieve "further instructions". At the time of analysis, the trojan simply retrieved another URL to access. It may store the contents of remote files retrieved in the Windows directory, such as winrtu32.exe.


Indications Of Infection
Presence of the file REGISTRY.EXE in the Windows directory (note this filename is not the same as REGEDIT.EXE) with an icon typically associated with the Registry Editor:
As the trojan uses a remote website, the effects of an infection may vary as the site is modified.

Virus Characteristics

A dropper of this trojans is believed to have been SPAMmed to many users. This trojan connects to a geocities.com user's site to retrieve a URL. It then navigates to that URL, passing the infected user's IP address and the string "Second,email_zasil". The trojan copies itself to the WINDOWS (%WinDir%) directory as REGISTRY.EXE and creates a registry run key to load itself at startup:

Windows 9x/ME:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\
Run "Registry Services" = C:\WINDOWS\REGISTRY.EXE <(Delete this Key)

Windows NT/2000/XP:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ Policies\Explorer\Run "0" = %windir%\registry.exe <(Delete this Key)

An additional key is also created:
HKEY_LOCAL_MACHINE\Software\Microsoft\DownloadManager <(Delete this Key)

The trojan is dropped by a file, often named MINENEW.EXE.PIF or MINENEW.MPG.PIF. <(Delete this file)


The dropper extracts a JPG file to the %Temp% folder and opens it. <(Delete this file)

This image is of pornographic nature.

for more info on trojans and their removal to www.thepublicworks.com security section and link to trojans, trojan ports, security dogs, firewalls and security, simovits consulting.
hope this helps, all the best
murve


Report Offensive Follow Up For Removal

Response Number 3
Name: Imp
Date: December 4, 2002 at 12:23:20 Pacific
Reply:

Hello Jennifer,
I am going to believe nobody is reading this forum before starting to edit a post !!!
Why to try to eradicate a trojan virus manually when you have in your hand program made to do it ?
Some trojan's are almost undtectables as for exemple BUGBEAR which has a random combination to hide itself under almost 50 differents names.....
you have a program called Trojan Remover which has all of them in his database !!!
Why don't you use it ? this is a freeware for one month !!!!
Trojan Remover :
http://www.simplysup.com/tremover/details.html


Report Offensive Follow Up For Removal







Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home



Results for: Manual Removal Downloader Trojan

How to remove Downloader.Trojan ?
    Summary: I also have the "downloader.trojan" virus and have gone through the same routine as "SweetLD215" in her previous posting here... I also have Norton and removed some of the infected files...turned off...
www.computing.net/answers/security/how-to-remove-downloadertrojan-/14592.html

Can't remove downloader.trojan
    Summary: I have the downloader.trojan virus and have followed the instructions on the Symantec website for removing it. However when I run the antivirus scan, it does not pick anything up. So then when I go in...
www.computing.net/answers/security/cant-remove-downloadertrojan/11723.html

download.trojan reinstalling
    Summary: Try this link and follow the instructions for removal Download.Trojan " You're only as safe as your last update " ...
www.computing.net/answers/security/downloadtrojan-reinstalling/17099.html








Which MP3 player do you have?

iPod/iPhone
Zune
Something Else
None


View Results

Poll Finishes Today.
Discuss in The Lounge
Poll History






Data Recovery Software