Comments
The Matrix 1.03 is a Polish
trojan. Because the client is a mix of Polish and English, we could not
determine all of the features. The server can have its registry key, file
name and port number changed prior to infection. The registry key and file
name are always the same, however. Thus, if the file name is iamatrojan.exe
then the registry key will be iamatrojan.
How To Remove
Quick fix: no quick
fix programs
Manual removal:
-
Remove the Encrypt
key in the registry located at HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
Which can be done with regedit or any other registry editing program.
-
Reboot the computer or
close Encrypt.exe.
-
Delete the trojan file
Encrypt.exe
in the windows directory.
|