Aliases
-
Backdoor-CCT
-
Backdoor.Nibu.E
-
TrojanSpy.Win32.Dumarin.g
Affected Operating Systems
Recovery Instructions:
Please follow the instructions for removing Trojans.
You will also need to edit the following registry entries, if they are present. Please read the warning about editing the registry.
At the taskbar, click Start|Run. Type 'Regedit' and press Return. The registry editor opens.
Before you edit the registry, you should make a backup. On the 'Registry' menu, click 'Export Registry File'. In the 'Export range' panel, click 'All', then save your registry as Backup.
Locate the HKEY_LOCAL_MACHINE entry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\load32
and delete it if it exists.
Each user has a registry area named HKEY_USERS\[code number indicating user]\. For each user locate the entry:
HKU\[code number]\Software\Microsoft\Windows NT\
CurrentVersion\Winlogon\Shell
and delete any reference to any file you deleted. Do not delete references to any other files.
Close the registry editor.
Delete the file fa4537ef.tmp in the Windows temp folder, if it exists.
Replace the Hosts file from a backup or edit it in Notepad to remove the changes that the Trojan has made. If you have not customised the HOSTS file, you can safely delete it.