<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Security and Tech Blogs &#187; Trojan</title>
	<atom:link href="http://www.precisesecurity.com/blogs/category/trojan-worm-virus/feed" rel="self" type="application/rss+xml" />
	<link>http://www.precisesecurity.com/blogs</link>
	<description></description>
	<lastBuildDate>Thu, 09 Feb 2012 00:49:48 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>Virus.Win32.Virut.ce</title>
		<link>http://www.precisesecurity.com/blogs/2009/02/11/viruswin32virutce</link>
		<comments>http://www.precisesecurity.com/blogs/2009/02/11/viruswin32virutce#comments</comments>
		<pubDate>Wed, 11 Feb 2009 09:26:34 +0000</pubDate>
		<dc:creator>webmaster</dc:creator>
				<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/?p=2439</guid>
		<description><![CDATA[<p><a href="http://www.precisesecurity.com/blogs">Security and Tech Blogs</a></p><p>Virus.Win32.Virut.ce can infect and overwrite files to be able to execute and spread itself. Virus.Win32.Virut.ce can also block access to security websites by modifying the Windows Hosts file. It can also inject malicious iframe on web files such as .HTM, .PHP or .ASP. The Trojan will badly infect .exe and .scr files on the computer resulting to severe malfunctions. Category: Trojan Horse Risk Level: High Aliases: W32.Virut.CF W32/Virut.n PE_VIRUX.A-1 W32/Scribble-A Virus:Win32/Virut.BM Technical Details Characteristics: Virus.Win32.Virut.ce will infect executable files under MS Windows systems. The virus is [...]</p>]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.precisesecurity.com/blogs">Security and Tech Blogs</a></p><p>Virus.Win32.Virut.ce can infect and overwrite files to be able to execute and spread itself. Virus.Win32.Virut.ce can also block access to security websites by modifying the Windows Hosts file. It can also inject malicious iframe on web files such as .HTM, .PHP or .ASP. The Trojan will badly infect .exe and .scr files on the computer resulting to severe malfunctions.</p>
<p><span id="more-2439"></span></p>
<p><strong>Category: </strong>Trojan Horse</p>
<p><strong>Risk Level: </strong>High</p>
<p><strong>Aliases:</strong></p>
<ul>
<li>W32.Virut.CF</li>
<li>W32/Virut.n</li>
<li>PE_VIRUX.A-1</li>
<li>W32/Scribble-A</li>
<li>Virus:Win32/Virut.BM</li>
</ul>
<h4>Technical Details</h4>
<p><strong>Characteristics:</strong><br />
Virus.Win32.Virut.ce will infect executable files under MS Windows systems. The virus is a Windows PE EXE file that is polymorphic in nature. This Trojan will embed malicious code into processes running on the compromised computer. Next, the code seizes critical system functions to trace running application and open files. Upon detecting an initiated application, it infects the main executable file. Since this is a polymorphic PE EXE virus, it will write its own code on expanded PE portion of file. This action will result to the adjustment of the program’s entry point, which leads to the execution of the virus code.</p>
<p>The virus may infect every executable item very badly. It renders the compromised file irrecoverable. Antivirus applications may attempt to remove part of the infected code but the result is catastrophic. What the virus does is irreversible.</p>
<p><strong>Distribution Method:</strong><br />
Computer users may acquire Virus.Win32.Virut.ce in various ways. Web site employing a drive-by-download method can instantly drop and execute this Trojan on visitor’s computer. Another means to spread this infection is through spam email messages and peer-to-peer network connections.</p>
<p>When it is set inside the computer, it monitors running processes and inject its code into the address space. It is intended to infect other executable files that have .exe and .scr extensions.</p>
<h2>Recommended Virus.Win32.Virut.ce Removal Procedure</h2>
<p>1. Temporarily Disable System Restore (Windows Me/XP). <a href="http://www.precisesecurity.com/how-to/ht-srxp.htm" target="_blank">[how to]</a><br />
2. Update the virus definitions.<br />
3. Reboot computer in SafeMode <a href="http://www.precisesecurity.com/how-to/ht-smode.htm" target="_blank">[how to]</a><br />
4. Run a full system scan and clean/delete all infected file(s)<br />
5. In order to make sure that threat is completely eliminated from your computer, carry out a full scan of your computer using AntiVirus and Antispyware Software. Another way to delete the virus using various Antivirus Program without the need to install can be done with <a href="http://www.precisesecurity.com/tools-resources/threat-removal-procedure/remove-threats-with-online-virus-scanner/" target="_blank">Online Virus Scanner</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.precisesecurity.com/blogs/2009/02/11/viruswin32virutce/feed</wfw:commentRss>
		<slash:comments>91</slash:comments>
		</item>
		<item>
		<title>go.google &#8211; go.yahoo</title>
		<link>http://www.precisesecurity.com/blogs/2008/11/16/gogoogle-goyahoo-redirects</link>
		<comments>http://www.precisesecurity.com/blogs/2008/11/16/gogoogle-goyahoo-redirects#comments</comments>
		<pubDate>Sun, 16 Nov 2008 09:59:24 +0000</pubDate>
		<dc:creator>webmaster</dc:creator>
				<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://www.precisesecurity.com/blogs/2008/11/16/gogoogle-goyahoo-redirects/</guid>
		<description><![CDATA[<p><a href="http://www.precisesecurity.com/blogs">Security and Tech Blogs</a></p><p>go.google, go.yahoo and go.msn are browser hijacker that dominantly redirect web browser to a fake online virus scanner web sites. go.google and go.yahoo existence is a result of a Trojan infection that has a payload of modifying browser settings, disable locally installed security programs and monitor Internet activity of the infected computer. go.google, go.yahoo and go.msn web sites do not exist. It is an error page created locally that is configured to redirect to various fake security web sites. The site will run a fake online virus [...]</p>]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.precisesecurity.com/blogs">Security and Tech Blogs</a></p><p>go.google, go.yahoo and go.msn are browser hijacker that dominantly redirect web browser to a fake online virus scanner web sites. go.google and go.yahoo existence is a result of a Trojan infection that has a payload of modifying browser settings, disable locally installed security programs and monitor Internet activity of the infected computer.<span id="more-1954"></span></p>
<p>go.google, go.yahoo and go.msn web sites do not exist. It is an error page created locally that is configured to redirect to various fake security web sites. The site will run a fake online virus scanner that later detects numerous types of computer infections. It will advise visitors to clean these threats using a recommended tool. However, before the program can proceed to its scan and detect features, user must purchase first the registration key. This tactic is a clear indication of a fraud activity perpetuated by fake antivirus applications.</p>
<p><strong>Screen Shot:</strong></p>
<p style="text-align: center;"><img class="aligncenter" title="security-tool-2010" src="http://www.precisesecurity.com/wp-content/uploads/2010/04/security-tool-2010.jpg" alt="go.google.com and go.yahoo.com" width="400" height="328" /></p>
<p><strong>Category: </strong>Trojan Horse</p>
<p><strong>Risk Level: Medium</strong></p>
<h4>Technical Details</h4>
<p><strong>Characteristics:</strong><br />
go.google.com, go.yahoo.com and go.msn.com are odd Internet browser behavior that can be attributed as browser hijacker. This infection is brought about by a Trojan infection that may also cause multiple system misbehavior. The obvious sign for this type of infection on the computer is having the home page or search result be forwarded to any of the mentioned deficient domains.</p>
<p>Once the Trojan invades the system, it will drop the following malicious files to accomplish its objective:<br />
<em>C:\Program Files\Mozilla Firefox\plugins\NPAskSBr.dll</em><br />
<em> C:\WINDOWS\karna.dat</em><br />
<em> C:\WINDOWS\system32\karna.dat</em><br />
<em> C:\WINDOWS\system32\dllcache\beep.sys</em><br />
<em> C:\WINDOWS\system32\wini10802.</em><br />
<em> C:\WINDOWS\system32\brastk.exe</em><br />
<em> C:\WINDOWS\system32\TDSS(four random characters).dll</em><br />
<em>C:\WINDOWS\system32\drivers\TDSSserv.sys</em><br />
<em> C:\WINDOWS\system32\drivers\TDSS(four random characters).sys</em></p>
<p>Next, it will conquer the registry to obtain start-up spot. It adds the following registry entries:<br />
<em>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\tdssdata</em><br />
<em> HKEY_LOCAL_MACHINE\SOFTWARE\tdss</em><br />
<em> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\brastk</em><br />
<em> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\brastk</em></p>
<h2>Recommended go.google &#8211; go.yahoo Removal Procedure</h2>
<p>Here is a simple step-by-step procedure to remove go.google &#8211; go.yahoo virus from an infected computer. Please follow the steps carefully.</p>
<p><strong>1.</strong> Download <a href="http://www.precisesecurity.com/tools-resources/adware-tools/malwarebytes-anti-malware">Malwarebytes’ Anti-Malware</a> (mbam-setup.exe) and save it on your Desktop or any accessible location of your hard drive.</p>
<p><strong>2.</strong> After downloading, double-click on the file to install the application.</p>
<p><strong>3.</strong> Follow the prompts and install the program using the “default” settings.</p>
<p><strong>4.</strong> Before the installation completes, check on the following prompts:<br />
- Update Malwarebytes’ Anti-Malware<br />
- Launch Malwarebytes’ Anti-Malware</p>
<p><strong>5.</strong> Click <strong>Finish</strong>. Program will run automatically and you will be prompt to update the program before starting a scan. Please proceed with update to obtain the latest database necessary to detect and remove go.google &#8211; go.yahoo.</p>
<p><strong>6.</strong> Scan your computer thoroughly and completely check all files, folders and registry entries for possible infection.</p>
<p><strong>7.</strong> When scanning is finished, click on <strong>Show Results</strong>.</p>
<p><strong>8.</strong> Make sure that all detected threats are marked, click on <strong>Remove Selected</strong>.</p>
<p><strong>9.</strong> After removing items associated with go.google &#8211; go.yahoo, it will prompt to restart the computer. Click <strong>Yes</strong> to complete the cleaning process.</p>
<p><strong>10.</strong> When computer starts, open MalwareBytes Anti-Malware. Go to <strong>Quarantine</strong> tab and click on <strong>Delete All</strong> to fully remove all malicious items.</p>
<p><em>Note: go.google &#8211; go.yahoo &#8211; go.msn infection may prevent mbam-setup.exe from downloading and running. You can download and rename this program from a different computer before running it on infected system.</em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.precisesecurity.com/blogs/2008/11/16/gogoogle-goyahoo-redirects/feed</wfw:commentRss>
		<slash:comments>80</slash:comments>
		</item>
		<item>
		<title>Trojan.Zlob.K</title>
		<link>http://www.precisesecurity.com/blogs/2006/04/22/trojanzlobk-removal-blogs</link>
		<comments>http://www.precisesecurity.com/blogs/2006/04/22/trojanzlobk-removal-blogs#comments</comments>
		<pubDate>Sat, 22 Apr 2006 04:55:13 +0000</pubDate>
		<dc:creator>webmaster</dc:creator>
				<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://precisesecurity.com/blogs/2006/04/22/trojanzlobk-removal-blogs/</guid>
		<description><![CDATA[<p><a href="http://www.precisesecurity.com/blogs">Security and Tech Blogs</a></p><p>Trojan.Zlob.K is a Trojan horse that may download and execute remote files and redirect Internet Explorer home page and search page to a different address. It may add encryption key to certain folders to hide associated files or any stolen data from the compromised computer. Category: Trojan Horse Risk Level: Low Aliases: TROJ_ZLOB.MU Trojan-Downloader.Win32.Zlob.s Downloader-XC Trojan.Zlob.B Technical Details Characteristics: Since Trojan.Zlob.K is a downloader, its goal is to download additional malware. It will communicate to predefined web sites, fetch malicious data, and run them on [...]</p>]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.precisesecurity.com/blogs">Security and Tech Blogs</a></p><p>Trojan.Zlob.K is a Trojan horse that may download and execute remote files and redirect Internet Explorer home page and search page to a different address. It may add encryption key to certain folders to hide associated files or any stolen data from the compromised computer. <span id="more-224"></span></p>
<p><strong>Category: </strong>Trojan Horse</p>
<p><strong>Risk Level: </strong>Low</p>
<p><strong>Aliases:</strong></p>
<ul>
<li>TROJ_ZLOB.MU</li>
<li>Trojan-Downloader.Win32.Zlob.s</li>
<li>Downloader-XC</li>
<li>Trojan.Zlob.B</li>
</ul>
<h4>Technical Details</h4>
<p><strong>Characteristics:</strong><br />
Since Trojan.Zlob.K is a downloader, its goal is to download additional malware. It will communicate to predefined web sites, fetch malicious data, and run them on the infected computer.</p>
<p>Once activated, the Trojan may drop the following files:<br />
<em>%System%\ncompat.tlb</em><br />
<em> %System%\interf.tlb</em><br />
<em> %System%\hp[RANDOM CHARACTERS].tmp</em></p>
<p>Then, it will add the following registry entry so that it executes on every Windows start-up:<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\&#8221;nvctrl.exe&#8221; = &#8220;nvctrl.exe&#8221;</p>
<p>To gain automatic start-up when running Windows Explorer, this Trojan will set the following registry entry:<br />
<em>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run</em><br />
<em> notepad.exe</em><br />
<em> msmsgs.exe</em></p>
<p>Additional registry entry that calls the application file msmsgs.exe is added. This will also allow Trojan.Zlob.K to run on every Windows start-up.<br />
<em>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon</em><br />
<em> Shell = “msmsgs.exe”</em></p>
<p>Lastly, the Trojan will hide malicious activities by injecting codes into legitimate file Explorer.exe.</p>
<p><strong>Distribution Method:</strong><br />
Trojan.Zlob.K may arrive on target computer by means of another Trojan infection.</p>
<h2>Recommended Trojan.Zlob.K Removal Procedure</h2>
<p>1. Temporarily Disable System Restore (Windows Me/XP). <a href="http://www.precisesecurity.com/how-to/ht-srxp.htm" target="_blank">[how to]</a><br />
2. Update the virus definitions.<br />
3. Reboot computer in SafeMode <a href="http://www.precisesecurity.com/how-to/ht-smode.htm" target="_blank">[how to]</a><br />
4. Run a full system scan and clean/delete all infected file(s)<br />
5. Delete/Modify any values added to the registry. <a href="http://www.precisesecurity.com/how-to/ht-regedit.htm" target="_blank">[how to edit registry]</a><br />
Navigate to and delete the following registry entry:<br />
<em>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\&#8221;nvctrl.exe&#8221;</em><br />
<em> = &#8220;nvctrl.exe&#8221;</em></p>
<p>6. Exit registry editor and restart the computer.<br />
7. In order to make sure that threat is completely eliminated from your computer, carry out a full scan of your computer using AntiVirus and Antispyware Software. Another way to delete the virus using various Antivirus Program without the need to install can be done with <a href="http://www.precisesecurity.com/tools-resources/threat-removal-procedure/remove-threats-with-online-virus-scanner/" target="_blank">Online Virus Scanner</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.precisesecurity.com/blogs/2006/04/22/trojanzlobk-removal-blogs/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Trojan.Galapoper.A</title>
		<link>http://www.precisesecurity.com/blogs/2006/04/20/trojangalapopera-removal-blogs</link>
		<comments>http://www.precisesecurity.com/blogs/2006/04/20/trojangalapopera-removal-blogs#comments</comments>
		<pubDate>Thu, 20 Apr 2006 09:16:51 +0000</pubDate>
		<dc:creator>webmaster</dc:creator>
				<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://precisesecurity.com/blogs/2006/04/20/trojangalapopera-removal-blogs/</guid>
		<description><![CDATA[<p><a href="http://www.precisesecurity.com/blogs">Security and Tech Blogs</a></p><p>Trojan.Galapoper.A is a computer infection that when executed will communicate to a remote server to download additional risks onto target system. This Trojan may also steal user’s data and send it to an attacker using HTTP POST protocol or email communication. Trojan.Galapoper.A and its variants habitually download Trojans from other groups of Downloaders, which may result to additional infections. Category: Trojan Horse Risk Level: Low Aliases: Trojan-Downloader.TIBS Trojan.Galapoper.A Trojan-Downloader.Win32.Tibs.il Tibs WORM_NUCRP.GEN Mal/TibsPak, Mal/HckPk-A, Troj/Tibs-Fam TrojanDownloader:Win32/Vxidl.gen!A Trojan-Downloader.Win32.Tibs Win-Trojan/Tibs.7346.DN Technical Details Characteristics: When executed, Trojan.Galapoper.A will avoid [...]</p>]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.precisesecurity.com/blogs">Security and Tech Blogs</a></p><p>Trojan.Galapoper.A is a computer infection that when executed will communicate to a remote server to download additional risks onto target system. This Trojan may also steal user’s data and send it to an attacker using HTTP POST protocol or email communication. Trojan.Galapoper.A and its variants habitually download Trojans from other groups of Downloaders, which may result to additional infections.<span id="more-219"></span></p>
<p><strong>Category: </strong>Trojan Horse</p>
<p><strong>Risk Level: </strong>Low</p>
<p><strong>Aliases:</strong></p>
<ul>
<li>Trojan-Downloader.TIBS</li>
<li>Trojan.Galapoper.A</li>
<li>Trojan-Downloader.Win32.Tibs.il</li>
<li>Tibs</li>
<li>WORM_NUCRP.GEN</li>
<li>Mal/TibsPak, Mal/HckPk-A, Troj/Tibs-Fam</li>
<li>TrojanDownloader:Win32/Vxidl.gen!A</li>
<li>Trojan-Downloader.Win32.Tibs</li>
<li>Win-Trojan/Tibs.7346.DN</li>
</ul>
<h4>Technical Details</h4>
<p><strong>Characteristics:</strong><br />
When executed, Trojan.Galapoper.A will avoid antivirus detection by applying a method of obfuscation. IT also performs the following set of operations:</p>
<ul>
<li>Inform an attacker of computer infection through email</li>
<li>Create a copy of itself to various locations of the compromised system</li>
<li>Drop a number of infected and clean files</li>
<li>Communicate to predefined web sites to execute more malware</li>
<li>Disable any installed antivirus, firewall, and other security-related software</li>
<li>Steal sensitive information and send the gathered data to a remote attacker via email or HTTP POST protocol</li>
</ul>
<p><strong>Distribution Method:</strong><br />
This Trojan will arrive on computer with filename “zhopaizdupla.exe.” It is dropped by another Trojan infection that is usually obtained from malicious web sites and unsecured peer-to-peer connection.</p>
<h2>Recommended Trojan.Galapoper.A Removal Procedure</h2>
<p>1. Temporarily Disable System Restore (Windows Me/XP). <a href="http://www.precisesecurity.com/how-to/ht-srxp.htm" target="_blank">[how to]</a><br />
2. Update the virus definitions.<br />
3. Reboot computer in SafeMode <a href="http://www.precisesecurity.com/how-to/ht-smode.htm" target="_blank">[how to]</a><br />
4. Run a full system scan and clean/delete all infected file(s)<br />
5. Delete/Modify any values added to the registry. <a href="http://www.precisesecurity.com/how-to/ht-regedit.htm" target="_blank">[how to edit registry]</a><br />
Navigate to and delete the following registry entry:<br />
<em>HKEY_CURRENT_USER = &#8220;WindowsSubVersion&#8221; = &#8220;[VALUE]&#8220;</em></p>
<p>6. Exit registry editor and restart the computer.<br />
7. In order to make sure that threat is completely eliminated from your computer, carry out a full scan of your computer using AntiVirus and Antispyware Software. Another way to delete the virus using various Antivirus Program without the need to install can be done with <a href="http://www.precisesecurity.com/tools-resources/threat-removal-procedure/remove-threats-with-online-virus-scanner/" target="_blank">Online Virus Scanner</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.precisesecurity.com/blogs/2006/04/20/trojangalapopera-removal-blogs/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Trojan.Zlob.J</title>
		<link>http://www.precisesecurity.com/blogs/2006/04/06/trojanzlobj-removal-blogs</link>
		<comments>http://www.precisesecurity.com/blogs/2006/04/06/trojanzlobj-removal-blogs#comments</comments>
		<pubDate>Thu, 06 Apr 2006 14:02:15 +0000</pubDate>
		<dc:creator>webmaster</dc:creator>
				<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://precisesecurity.com/blogs/2006/04/06/trojanzlobj-removal-blogs/</guid>
		<description><![CDATA[<p><a href="http://www.precisesecurity.com/blogs">Security and Tech Blogs</a></p><p>Trojan.Zlob.J is a member of a Zlob family that refers to a large group of malware involving in malicious acts like modifying Internet browsers, redirect home page and search results, install fake security applications, and execute arbitrary file from a remote server. Trojan.Zlob.J also allows a remote attacker to access the compromised computer. Thus, the attacker may perform malicious actions and steal sensitive data from the infected system. Category: Trojan Horse Risk Level: Medium Technical Details Characteristics: Upon execution, Trojan.Zlob.J will drop the following harmful [...]</p>]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.precisesecurity.com/blogs">Security and Tech Blogs</a></p><p>Trojan.Zlob.J is a member of a Zlob family that refers to a large group of malware involving in malicious acts like modifying Internet browsers, redirect home page and search results, install fake security applications, and execute arbitrary file from a remote server. Trojan.Zlob.J also allows a remote attacker to access the compromised computer. Thus, the attacker may perform malicious actions and steal sensitive data from the infected system.<span id="more-183"></span></p>
<p><strong>Category: </strong>Trojan Horse</p>
<p><strong>Risk Level: </strong>Medium</p>
<h4>Technical Details</h4>
<p><strong>Characteristics:</strong><br />
Upon execution, Trojan.Zlob.J will drop the following harmful files:<br />
<em>%System%\ld[RANDOM CHARACTERS].tmp</em><br />
<em> %System%\dfrgsrv.exe</em></p>
<p>To gain automatic start-up spot, the Trojan will modify Windows registry and add the following entry:<br />
<em>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run</em><br />
<em> &#8220;wininet.dll&#8221; = &#8220;dfrgsrv.exe&#8221;</em></p>
<p>Alternative start-up method is to inject malicious code into the following Windows process that runs when Windows starts:<br />
<em>winlogon.exe</em></p>
<p>Once running on the compromised system, Trojan.Zlob.J will monitor Internet activities and may modify settings of the home page.<br />
Lastly, the Trojan will establish an HTTP connection to specified URL and performs the following actions:</p>
<ul>
<li>Ping the remote computer</li>
<li>Send a status report regarding the infected system</li>
<li>Download and execute remote files, which upgrade itself</li>
</ul>
<p><strong>Distribution Method:</strong><br />
Trojan.Zlob.J uses the web primarily to spread a copy of itself. Malicious web sites, infected web pages and unsafe file-sharing networks are the top sources of this Trojan. Once inside the computer, it may contaminate other files locally but will never spread on neighboring computers.</p>
<h2>Recommended Trojan.Zlob.J Removal Procedure</h2>
<p>1. Temporarily Disable System Restore (Windows Me/XP). <a href="http://www.precisesecurity.com/how-to/ht-srxp.htm" target="_blank">[how to]</a><br />
2. Update the virus definitions.<br />
3. Reboot computer in SafeMode <a href="http://www.precisesecurity.com/how-to/ht-smode.htm" target="_blank">[how to]</a><br />
4. Run a full system scan and clean/delete all infected file(s)<br />
5. Delete/Modify any values added to the registry. <a href="http://www.precisesecurity.com/how-to/ht-regedit.htm" target="_blank">[how to edit registry]</a><br />
Navigate to and delete the following registry entry:<br />
<em>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run</em> <em> &#8220;wininet.dll&#8221; = &#8220;dfrgsrv.exe&#8221;</em><em></em><em></em></p>
<p>6. Exit registry editor and restart the computer.<br />
7. In order to make sure that threat is completely eliminated from your computer, carry out a full scan of your computer using AntiVirus and Antispyware Software. Another way to delete the virus using various Antivirus Program without the need to install can be done with <a href="http://www.precisesecurity.com/tools-resources/threat-removal-procedure/remove-threats-with-online-virus-scanner/" target="_blank">Online Virus Scanner</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.precisesecurity.com/blogs/2006/04/06/trojanzlobj-removal-blogs/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

