Danrit manual removal:
Kill processes:
notesweb.exe, win052.exe
Delete registry values:HKEY_LOCAL_MACHINE\SOFTWARE\Public Domain\Blat
Delete files:notesweb.exe, win052.exe, se.bat, sos0.bat, sos1.bat, sos2.bat, sos3.bat, sos4.bat, symantecav.lnk
Misc:Exact file location:
notesweb.exe, symantecav.lnk - C:\Documents and Settings\All Users\Start Menu\Programs\Startup
win052.exe - C:\Windows\System, C:\Windows\System32 or C:\Winnt\System32
se.bat, sos0.bat, sos1.bat, sos2.bat, sos3.bat, sos4.bat, sos5.bat - C:\Windows\Temp or C:\Winnt\Temp
The backdoor also drops blat.exe and ntrights.exe files, which are legitimate applications used to send e-mail messages and manage Windows user accounts. They can be found in C:\Windows\Temp or C:\Winnt\Temp folder.
Danrit creates several scheduled tasks.
The threat opens TCP port 49495.
Post Comment: