Comments
Shadow Phrye is an older
trojan. When Shadow Phrye is started, it chooses a random TCP port to listen
for connections. Then the server goes online to #shadowphrye on IRC and
broadcasts your IP and what port it has chosen to listen on. Even though
the readme file for Shadow Phyre says it is impossible to manually remove,
it is not. As of November 2000 we checked the #shadowphyre channel and
it exists. However there were no servers broadcasting their IP and port
to this IRC channel.
How To Remove
Quick fix: no quick
fix programs
Manual removal:
-
Remove the WinZipp
key in the registry located at HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
and the INET Wizard key in the registry located
at HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices.
Which
can be done with regedit or any other registry editing program.
-
Reboot the computer or
close whichever of the following is running: trance.exe,
WinZipp.exe
or inet.exe.
-
Delete the trojan files
inet.exe
and
WinZipp.exe both
in the windows system directory.
|