Comments
SniperNet 2.1 is a beta
trojan. It was programmed in Visual Basic 5. It does try to be sneaky and
load via the runservicesonce (first we have seen doing this). Also when
we tested it, it left off a / in the path written to the registry. So,
it may not actually auto load correctly.
How To Remove
Quick fix: no quick
fix programs
Manual removal:
-
Write down the data (path
and filename) in the Network
Solutions Client Applikation Service
key and then remove it from the registry located at HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
Which can be done with regedit or any other registry editing program.
-
Reboot the computer or
close the file listed in the registry.
-
Delete the trojan file
listed in the registry.
|