Resolve for Surila-E

A tool that remove Surila-E trojan
Download

Resolve for Surila-E Ranking & Summary

Advertisement

  • Rating:
  • License:
  • Freeware
  • Publisher Name:
  • Sophos Plc
  • Operating Systems:
  • Windows All
  • File Size:
  • 77 KB

Resolve for Surila-E Tags


Resolve for Surila-E Description

Resolve is the name for a set of small, downloadable Sophos utilities designed to remove and undo the changes made by certain viruses, Trojans and worms. They terminate any virus processes and reset any registry keys that the virus changed. Existing infections can be cleaned up quickly and easily, both on individual workstations and over networks with large numbers of computers. Troj/Surila-E is a backdoor Trojan which allows a remote intruder to gain access and control over the computer. Troj/Surila-E includes functionality to access the internet and communicate with a remote server via HTTP. When first run Troj/Surila-E copies itself to: csrss.exe msupdate.exe and creates a file dodrrr.exe detected as Troj/Surila-D. Troj/Surila-E modifies the system file sfc_os.dll in an attempt to disable the Windows System File Checker. The Trojan may do this in order to modify further system files. The following registry entries are created to run msupdate.exe on startup: HKCUSoftwareMicrosoftWindowsCurrentVersionRun msupdate msupdate.exe HKLMSOFTWAREMicrosoftWindowsCurrentVersionRun msupdate msupdate.exe HKLMSOFTWAREMicrosoftWindowsCurrentVersionRunOnce msupdate msupdate.exe Registry entries are set as follows: HKCUSoftwareMicrosoftInternet Explorer mtxqwnm nVKHFQU HKCUSoftwareMicrosoftInternet Explorer veer 40040 HKCUSoftwareMicrosoftWindowsCurrentVersionPolicies DisableRegistryTools 0 HKLMSOFTWAREMicrosoftWindowsCurrentVersionpolicies DisableRegistryTools 0 HKLMSOFTWAREMicrosoftOle WINRUN msupdate.exe HKLMSOFTWAREMicrosoftWindows NTCurrentVersionWinlogon SFCScan 0 HKLMSYSTEMCurrentControlSetControlLsa WINRUN msupdate.exe HKLMSOFTWAREMicrosoftWindows NTCurrentVersionWinlogon SFCDisable ffffff9d Troj/Surila-E can be removed from Windows computers automatically with the following Resolve tools: Windows disinfector SURILGUI is a disinfector for standalone Windows computers. To use it you have to do the following: · Open SURILGUI.com file from your desktop after downloading it. · Click on the Start Scan Button. · Wait for the process to complete. Command line disinfector SURILSFX.EXE is a self-extracting archive containing SURILCLI, a Resolve command line disinfector for use by system administrators on Windows networks.


Resolve for Surila-E Related Software