Computing.Net > Forums > Security and Virus > Manual Removal Downloader Trojan

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

Manual Removal Downloader Trojan

Reply to Message Icon

Name: Jennifer SUMN
Date: December 3, 2002 at 12:57:11 Pacific
OS: Various
CPU/Ram: Various
Comment:

Does anyone have manual removal instructions for the Downloader Trojan? Thanks...



Sponsored Link
Ads by Google

Response Number 1
Name: Latika
Date: December 3, 2002 at 13:44:03 Pacific

Response Number 2
Name: murve
Date: December 3, 2002 at 13:58:57 Pacific
Reply:

hi jennifer,
here's some info on how to delete this trojan:
the alias' for this trojan are:
Troj/Zasil-A (Sophos), Trojan.Zasil (Symantec), TrojanClicker.Win32.Zasil (AVP)

Method Of Infection:
This trojan connects to a remote website to retrieve "further instructions". At the time of analysis, the trojan simply retrieved another URL to access. It may store the contents of remote files retrieved in the Windows directory, such as winrtu32.exe.


Indications Of Infection
Presence of the file REGISTRY.exe in the Windows directory (note this filename is not the same as REGEDIT.EXE) with an icon typically associated with the Registry Editor:
As the trojan uses a remote website, the effects of an infection may vary as the site is modified.

Virus Characteristics

A dropper of this trojans is believed to have been SPAMmed to many users. This trojan connects to a geocities.com user's site to retrieve a URL. It then navigates to that URL, passing the infected user's IP address and the string "Second,email_zasil". The trojan copies itself to the WINDOWS (%WinDir%) directory as REGISTRY.exe and creates a registry run key to load itself at startup:

Windows 9x/ME:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\
Run "Registry Services" = C:\WINDOWS\REGISTRY.exe <(Delete this Key)

Windows NT/2000/XP:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ Policies\Explorer\Run "0" = %windir%\registry.exe <(Delete this Key)

An additional key is also created:
HKEY_LOCAL_MACHINE\Software\Microsoft\DownloadManager <(Delete this Key)

The trojan is dropped by a file, often named MINENEW.exe.PIF or MINENEW.MPG.PIF. <(Delete this file)


The dropper extracts a JPG file to the %Temp% folder and opens it. <(Delete this file)

This image is of pornographic nature.

for more info on trojans and their removal to www.thepublicworks.com security section and link to trojans, trojan ports, security dogs, firewalls and security, simovits consulting.
hope this helps, all the best
murve


0

Response Number 3
Name: Imp
Date: December 4, 2002 at 12:23:20 Pacific
Reply:

Hello Jennifer,
I am going to believe nobody is reading this forum before starting to edit a post !!!
Why to try to eradicate a trojan virus manually when you have in your hand program made to do it ?
Some trojan's are almost undtectables as for exemple BUGBEAR which has a random combination to hide itself under almost 50 differents names.....
you have a program called Trojan Remover which has all of them in his database !!!
Why don't you use it ? this is a freeware for one month !!!!
Trojan Remover :
http://www.simplysup.com/tremover/details.html


0

Sponsored Link
Ads by Google
Reply to Message Icon

Related Posts

See More







Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: Manual Removal Downloader Trojan

How to remove Downloader.Trojan ? www.computing.net/answers/security/how-to-remove-downloadertrojan-/14592.html

Can't remove downloader.trojan www.computing.net/answers/security/cant-remove-downloadertrojan/11723.html

download.trojan reinstalling www.computing.net/answers/security/downloadtrojan-reinstalling/17099.html