Title: Danrit
Type: Backdoors

Remove Danrit. Removal instructions


 
Severity scale:Danrit severity is 81  (81 / 100)
 
Danrit is a dangerous backdoor that provides the attacker with unauthorized remote access to a compromised computer. The parasite arrives in executable file, which has the icon of Adobe Acrobat document. Once the user runs such file, the backdoor installs itself to the system and attempts to launch Adobe Acrobat and open a predetermined local document in order to trick the user into thinking that a valid PDF file was opened. Then Danrit runs a payload. It opens a back door, which allows the intruder to run programs on a compromised computer, and starts logging all user keystrokes. Gathered data is sent to a predefined e-mail address every day from Monday to Thursday. The backdoor also creates a user account with the administrator's privileges. Danrit can automatically uninstall itself and remove all traces of its presence in the system. Every Friday it will terminate own processes, delete all related objects, created scheduled tasks and added user account. Danrit automatically runs on every Windows startup.

Danrit properties:
• Allows remote user connection
• Sends out logs by FTP or email
• Logs keystrokes
• Hides from the user
• Stays resident in background

Automatic Danrit removal:

SpyHunter is recommended remover to uninstall Danrit. You should confirm using free trial that it detects current version of parasite.

Note: Manual assistance required means that one or all of removers were unable to remove parasite without some manual intervention, please read manul removal instructions below.

If you failed to remove Danrit using SpyHunter please report this to us.

We might be affiliated with any product we recommend on the site. Full disclosure in our Agreement of Use.
STOPzilla
We are testing STOPzilla's efficiency at removing Danrit (2005-11-16 06:36:46)
Malwarebytes Anti Malware
We are testing Malwarebytes Anti Malware's efficiency at removing Danrit (2005-11-16 06:36:46)
Spyware Doctor
We are testing Spyware Doctor's efficiency at removing Danrit (2005-11-16 06:36:46)
XoftSpySE Anti Spyware

Danrit manual removal:

Kill processes:
notesweb.exe, win052.exe
Delete registry values:
HKEY_LOCAL_MACHINE\SOFTWARE\Public Domain\Blat
Delete files:
notesweb.exe, win052.exe, se.bat, sos0.bat, sos1.bat, sos2.bat, sos3.bat, sos4.bat, symantecav.lnk
Misc:
Exact file location:
notesweb.exe, symantecav.lnk - C:\Documents and Settings\All Users\Start Menu\Programs\Startup
win052.exe - C:\Windows\System, C:\Windows\System32 or C:\Winnt\System32
se.bat, sos0.bat, sos1.bat, sos2.bat, sos3.bat, sos4.bat, sos5.bat - C:\Windows\Temp or C:\Winnt\Temp

The backdoor also drops blat.exe and ntrights.exe files, which are legitimate applications used to send e-mail messages and manage Windows user accounts. They can be found in C:\Windows\Temp or C:\Winnt\Temp folder.

Danrit creates several scheduled tasks.

The threat opens TCP port 49495.
Information added: 2005-11-16 03:59:31
Information updated: 2005-11-16 03:59:31

Additional resources related to Danrit:

Attention: If you know or you have a website or page about Danrit removal, feel free to add a link to this list: add url

more resources

Post Comment:

Attention: Use this form only if you have additional information about Danrit parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.
Home page Name



«


* All field required
Latest spyware news:
Subscribe to news

Similar parasites:
Compare spyware removers
Compare free products

HijackThis Log Analyzer Beta 2 HijackThis Log Analyzer Beta 2

I failed to remove Danrit using SpyHunter.

Email


Close

Spreading the knowledge:

It is very hard to fight Computer parasites alone in internet space. If you have a website we would be more than happy if you would help us to spread the knowledge about latest threats. You can help your visitors to manage their Computer system manually without aditional expences. Knowledge is the power, we just need to spread it.
add text box
rss feed
help other