Discovered: March 20, 2008
Updated: March 20, 2008 5:21:47 AM
Type: Trojan
Infection Length: 11,264 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Vista, Windows XP
Trojan.Dronjaga
Risk Level 1: Very Low
When executed, the Trojan copies itself as the following file:
%System%\userinit.exe
The original version of the above file is copied as the following file:
%System%\userini.exe
The compromised computer is unable to restart.
The Trojan attempts to download a potentially malicious file from the following URL:
[http://]djaga-djaga.cn/harisma/gate[REMOVED]
This url is no longer available wonder why???? please dont attempt too unless you know what you doing and if you do be cool to talk to you.
Removing the beast is as follows:
- Restart the computer using the Windows Recovery Console
- Disable System Restore (Windows......