Sunday, June 28, 2009
Stop Trojan Infections
A simple way to disable any virus,worm or trojan from entering your USB drive, is to create a folder by the name of ‘autorun.inf’.Once this is done, right click on the folder ,navigate to properties ,hide the folder as well as write protect it.This works as well with a text file of the same.This ensures that even if a virus,trojan or worm does get into the USB drive.It does not being to operate as soon as the drive is connected to my computer.
Sunday, April 12, 2009
VundoFix - Freeware Removal Tool for Trojan.Vundo
If you are experiencing problems with pop-ups, ad software, spyware, or malware (or if your computer is acting strangely), you should scan it with VundoFix.
VundoFix 7.0.6 - A useful application that will clean Virtumonde viruses from your computer. VundoFix.exe is a removal tool developed to remove Virtumonde infections. If you are infected, you will be bombarded with popups for WinFixer, Amaena, WinAntiVirus, ErrorSafe, SystemDoctor and DriveCleaner. Downloading and running these Fraudware applications will result in a fake scan telling you that you are infected with malware then telling you that you need to buy their program to remove the malware that it found.They are scams and will not remove anything but could possibly make your infection worse.
How to use VundoFix:
VundoFix |Freeware|117KB|
HomePage|OS :Win9x/Me/NT/2000/XP/2003
Friday, February 20, 2009
TrojanDropper Removal Instructions
A Trojan dropper is usually a standalone program that drops different type of standalone malware (trojans, worms, backdoors) to a system .It opens up a large security hole on your computer and is a very dangerous threat to the security of your personal and financial data.It may download large amounts of spyware and adware that automatically install themselves onto your system.Trojan.Dropper/AdobeFake is generally downloaded from the Internet and installed via, spam email, adult websites or file sharing programs without users knowledge.
Symptoms
Manual Removal Instructions
Step 1 : Use Windows File Search Tool
- Start > Search > All Files or Folders.
- In the "All or part of the the file name" section, type in "TrojanDropper" file name(s).
- To get better results, select "Look in: Local Hard Drives" or "Look in: My Computer" and then click "Search" button.
- When Windows finishes your search, hover over the "In Folder" of "TrojanDropper", highlight the file and copy/paste the path into the address bar. Save the file's path on your clipboard because you'll need the file path to delete TrojanDropper in the following manual removal steps.
Step 2 : Use Windows Task Manager
- Press CTRL+ALT+DEL
- Remove the "TrojanDropper" processes files:
search[2].exe sysrtmvs.exe senh.exe wd7gi8nnew.exe visfx500new.exe OEM.exe numbsoftnew.exe Mendoza1.exe Mendoza.exe
Step 3 : Remove TrojanDropper Registry Values
- Start > Run > type regedit and then press the "OK" button.
- Locate and delete the entry or entries whose data value (in the rightmost column) is the spyware file(s) detected earlier.
- To delete "TrojanDropper" value, right-click on it and select the "Delete" option.
- Locate and delete "TrojanDropper" registry entries
HKEY_LOCAL_MACHINESoftware\Microsoft\Windows\CurrentVersion\Emitt
Useful Softwares for TrojanDropper Removal
- Download SpyHunter's Malware Scanner
- Download Threat Fire
- Download XoftSpy SE
- Download SpywareDoctor
Precautions & Preventions
- Download & update your Windows Security up-to-date
- Always install a good anti-spyware software & its definitions should be up-to-date
- Install and keep your firewall turned on.
Thursday, November 20, 2008
Sinowal, The Super-Trojan
A single computer virus, owned by one criminal gang, has compromised hundreds of thousands of online bank accounts worldwide, according to security experts at the RSA FraudAction Research Lab.
That's Sinowal, a super-Trojan that uses a technique called HTML injection to put ersatz information on your browser's screen. The bad info prompts you to type an account number and/or a password. Of course, Sinowal gathers all the information and sends it back home — over a fancy, secure, encrypted connection, no less.
Sinowal operates like many other viruses – injecting corrupt data into Web pages that are usually known and trusted by the victim, and which attack a computer through loopholes in a Web browser (media players are a popular way in). The virus can then prompt the victim to offer confidential information, such as bank account details. More than 2700 bank and e-commerce sites worldwide have been affected by this one Trojan.
Where it differs is not only is Sinowal being constantly updated with patches to beat security filters - it is also storing up user data on everyone its infects, which means it requires major data storage facilities.
Sinowal/Mebroot works by infecting Windows XP's Master Boot Record (MBR) — it takes over the tiny program that's used to boot Windows. MBR infections have existed since the dawn of DOS.
Once Sinowal/Mebroot is in your system, the Trojan runs stealthily, loading itself in true rootkit fashion before Windows starts. The worm flies under the radar by running inside the kernel, the lowest level of Windows, where it sets up its own network communication system, whose external data transmissions use 128-bit encryption. The people who run Sinowal/Mebroot have registered thousands of .com, .net, and .biz domains for use in the scheme.
Sinowal/Mebroot cloaks itself entirely and uses no executable files that you can see. The changes it makes to the Registry are very hard to find. Also, there's no driver module in the module list, and no Sinowal/Mebroot-related svchost.exe or rundll32.exe processes appear in the Task Manager's Processes list
Apparently Sinowal has been successful enough to compromise 270,000 bank accounts and 240,000 credit and debit cards across the US, UK, Australia and Poland.
The main method of delivery isn’t email spam, though, but instead through hacking websites to insert the malicious code onto visitors PC’s.Wordpress blogs have especially become a major target of attack, not least due to users failing to keep their software updated with patches.
Your firewall won't help: Sinowal/Mebroot bypasses Windows' normal communication routines, so it works outside your computer's firewall.
Your antivirus program may help, for a while. Time and time again, however, Sinowal/Mebroot's creators have modified the program well enough to escape detection. AV vendors scramble to catch the latest versions, but with one or two new Sinowal/Mebroot iterations being released every month, the vendors are trying to hit a very fleet — and intelligent — target.
You can't rely on rootkit scanners for protection. Even the best rootkit scanners miss some versions of Sinowal/Mebroot.
Source:BBC-News/Technology
Saturday, September 27, 2008
Trojan-Spy.win32.BHO Removal
Trojan-Spy.win32.BHO is fake infection. This warning is displayed by rogue anti-viruses in order to gain a purchase. The most majority of corrupt security tools use intimidating strategy to make people interested into paid version.
Trojan-Spy.win32.BHO Automatic Removal Instructions
First Step: Print or bookmark these instructions because you’ll have to reboot into Safe Mode. Also back up your computer in case you make a mistake.
- Download and save SmitFraudFix to your desktop.
- How to run SmitfraudFix-> tutorial is here
- Restart your computer in Safe Mode .
- Go to C:\Windows\Temp, click Edit, click Select All, press DELETE, and then
click Yes to confirm that you want all the items to go to the Recycle Bin. - Go to C:\Documents and Settings\[LISTED USER]\Local Settings\Temp, click Edit, click Select All, press DELETE, and then click Yes to confirm that
you want all the items to go to the Recycle Bin. - Reboot your computer back to normal mode. Go to Windows Update and download all critical updates.
Trojan-Spy.win32.BHO Manual Removal Instructions
First Step: Close all programs and Internet browsers. Also back up your computer in case you make a mistake and your computer stops working.
- Uninstall Trojan-Spy.win32.BHO Program
Click on Start > Settings > Control Panel > Double-click on Add/Remove Programs. Search for and uninstall Trojan-Spy.win32.BHO if found. - To stop Trojan-Spy.win32.BHO processes (view process removal steps)
Go to Start > Run > type taskmgr. The click the Processes tab and you’ll see a list of running processes.Search and stop these Trojan-Spy.win32.BHO processes:
Antvrs.exe
vav.exe
microAV.exe
For each unwanted process, right-click on it and then select “End task”. - To unregister Trojan-Spy.win32.BHO registry keys (view registry keys removal steps)
Go to Start > Run > type regedit > press OK. Edit the value (on the right pane) by right-clicking on it and selecting the Modify option. Select the Delete option. Search and delete these Trojan-Spy.win32.BHO registry keys .HKEY_CURRENT_USER\Software\Antivirus
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"Antivirus" = "%ProgramFiles%\Vista Antivirus 2008\Antvrs.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Antivirus - If your homepage has been changed, go to Start > Control Panel > Internet Options > click on the General > click Use Default under Home Page. Add the your desired default homepage, then click Apply > click OK. Open a new web browser to check that you have your desired default homepage.
- Remove Trojan-Spy.win32.BHO Directories.
To find Trojan-Spy.win32.BHO directories, go to Start > My Computer > Local Disk (C:) > Program Files > Show the contents of this folder.
Search and delete the following Trojan-Spy.win32.BHO directories:
C:\Program Files\MicroAntivirus
C:\Program Files\Vista Antivirus 2008
Right-click on the Trojan-Spy.win32.BHO folder and select Delete.
A message will popup ‘Are you sure you want to remove the folder Trojan-Spy.win32.BHO and move all its contents to the Recycle Bin?’, click Yes.
Another message will appear saying ‘Renaming, moving or deleting Trojan-Spy.win32.BHO could make some programs not work. Are you sure you want to do this?’, click Yes. - To remove Trojan-Spy.win32.BHO icons on your Desktop, drag and drop them to the Recycle Bin.
Monday, April 7, 2008
Backdoor Trojans

A backdoor trojan differs from a trojan in that it also opens a backdoor to your system.A trojan is a malicious application that appears to do one thing, but actually does another.Examples of backdoor trojans are Netbus or Back Orifice.They are so dangerous because they have the potential to allow remote adminstration of your system.This gives an attacker unauthorized access to a machine and the means for remotely controlling the machine without the user's knowledge. A Backdoor compromises system integrity by making changes to the system that allow it to be used by the attacker for malicious purposes unknown to the user.
- Use your system and Internet connection to send spam (yes, the majority of spam is now generated by infected systems).
- Steal your online and offline passwords, credit card numbers, address, phone number, and other information stored on your computer that could be used for identity theft, or other financial fraud.
- Log your activity, read email, view and download contents of documents, pictures, videos and other private data.
- Use your computer and Internet connection, in conjunction with others to launch Distributed Denial of Service (DDoS) attacks.
- Modify system files, disable antivirus, delete files, change system settings, to cover tracks, or just to wreak havoc.

How to tackle this ?
Download SDFix.exe and save it to your desktop:
SDFix
- Double click on SDFix on your desktop,and install the fix to C:\
Please then reboot your computer into Safe Mode by doing the following:
- Restart your computer
- After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
- Instead of Windows loading as normal, a menu with options should appear;
- Select the first option, to run Windows in Safe Mode, then press "Enter".
- Choose your usual account.
- In Safe Mode,go to and open the C:\SDFix folder,then double click on RunThis.bat to start the script.
- Type Y to begin the script.
- It will remove the Trojan Services then make some repairs to the registry and prompt you to press any key to Reboot.
- Press any Key and it will restart the PC.
- Your system will take longer that normal to restart as the fixtool will be running and removing files.
- When the desktop loads the Fixtool will complete the removal and display Finished, then press any key to end the script and load your desktop icons.
Download the UNDO.ZIP file and unzip it with a program like WinZip. Double click the undo.reg file to import it into the registry. For the curious, the contents of the REG file are:
Click Start, then Run, then type "c:\windows\win.ini" in the text box,then click OK. Scroll down to the line that begins with "run=" and if it loads the trojan program, delete it.Click Start, then Run, then type "c:\windows\system.ini" in the text box,then click OK.Scroll down to the line that begins with "shell=" and if it loads the trojan program,be very careful to delete only the part that loads the trojan.After you are done the shell= should look like this:shell=Explorer.exe
Another Utilities & Procedures
Procedure #1
Download the following four items
McAfee Stinger
Trend Sysclean Package
Latest Trend Virus Pattern Files. (example; lpt285.zip*)
(*The file name lpt285.zip is simply an example name of the file and you'll find the filename posted at TrendMicro will have a higher number than 285. Each time TrendMicro produces new Pattern Files the number in the file name will be incremented accordingly.)
Ad-Aware SE (free personal edition)
- Create a new directory.
On drive "C:\"
(e.g., "c:\New Folder")
or the desktop
(e.g., "C:\Documents and Settings\username\Desktop\New Folder") - Place SYSCLEAN.COM (the Trend Sysclean Package referenced above) into the new directory you created. Extract the latest Trend Virus Pattern Files (Example: lpt$vpn.285 and WHATSNEW.TXT) from the zip file you downloaded above into the same new directory you created. The Trend Pattern File contained in the ZIP file must be placed in the same directory as SYSCLEAN.COM!
- Important: The TrendMicro Pattern file is updated reguarly. Aywhere from once per day to a few times in a day. Always make sure you have the latest version of SYSCLEAN.COM and the Pattern File before you scan your platform. The McAfee Stinger Internet worm and Trojan removal tool is upgraded periodically. Always make sure you have the latest version of McAfee Stinger utility before you scan your platform.
- Install and Update Ad-Aware with the latest definitions.
- If you are using WinME or WinXP, disable System Restore.
Disable SysRestore Procedure - Reboot your PC into Safe Mode [F8 key during boot process].
How to Boot Into Safe Mode:
Generic
Windows XP
How to perform a clean boot in Windows XP - Using McAfee Stinger, the Trend Sysclean utility and Ad-Aware, perform a Full Scan of your platform and clean and/or delete any infectors and/or parasites found (a few cycles may be needed).
- Restart your PC and perform a "final" Full Scan of your platform using McAfee Stinger, the Trend Sysclean utility and Ad-Aware.
- If you are using WinME or WinXP,Re-enable System Restore and re-apply any System Restore preferences (e.g. HD space to use suggested 400 ~ 600MB).
- Reboot your PC.
- If you are using WinME or WinXP, create a new Restore point
Download MULTI_AV.EXE from the here
Multi AV
To use this utility, perform the following...
Execute; Multi_AV.exe { Note: You must use the default folder C:\AV-CLS }
Choose; Unzip
Choose; Close
Execute; C:\AV-CLS\StartMenu.BAT
{ or Double-click on 'Start Menu' in C:\AV-CLS }
NOTE: You may have to disable your software FireWall or allow WGET.EXE to go through your
FireWall to allow it to download the needed AV vendor related files.
C:\AV-CLS\StartMenu.BAT -- { or Double-click on 'Start Menu' in C:\AV-CLS}
This will bring up the initial menu of choices and should be executed in Normal Mode.
This way all the components can be downloaded from each AV vendor's web site.
The choices are; Sophos, Trend, McAfee, Kaspersky, Exit this menu and Reboot the PC.
You can choose to go to each menu item and just download the needed files or you can
download the files and perform a scan in Normal Mode. Once you have downloaded the files
needed for each scanner you want to use, you should reboot the PC into Safe Mode [F8 key
during boot] and re-run the menu again and choose which scanner you want to run in Safe
Mode. It is suggested to run the scanners in both Safe Mode and Normal Mode.
When the menu is displayed hitting 'H' or 'h' will bring up a more comprehensive PDF help
file.
Additional Instructions: here

Also check the following
Symantec
Backdoor SDBot.H Trojan
BackDoor-ABH
Backdoor:Win32/zonebac_gen!B FindAWF




