Main > Free Download Search >

Free resolve software for windows

resolve

Sponsored Links
Sponsored Links
Secleted [ 0 ] software to compare
Results 1 - 15 of about 942
Resolve 1.0

Resolve 1.0


Windows Version of NSLOOKUP. Tells host name given theIP address or host name from IP address. more>>
Windows Version of NSLOOKUP. Tells host name given theIP address or host name from IP address.
<<less
Download (66K)
Added: 1998-12-31 License: Freeware Price:
3992 downloads
IpDnsResolver 1.2

IpDnsResolver 1.2


IpDnsResolver lets you find your IP address, resolve hostnames to IP addresses using the DNS more>>
IpDnsResolver is a very simple and fast program that easily lets you find your own IP address, resolve hostnames to IP addresses and IP addresses to hostnames using the DNS.
<<less
Download (424KB)
Added: 2005-10-24 License: Freeware Price:
1562 downloads
 
Other version of IpDnsResolver
IpDnsResolver 1.2Lets you find your IP address, resolve hostnames to IP addresses using the DNS. IpDnsResolver 1.2 - Nsasoft LLC ... IpDnsResolver is a very simple
License:Freeware
Download (420KB)
1766 downloads
Added: 2005-03-25
FastResolver 1.22

FastResolver 1.22


FastResolver is a small utility that resolves multiple host names into IP addresses/MAC Addresses and vice versa. more>>

FastResolver is a small utility that resolves multiple host names into IP addresses and vice versa. You can simply type the list of IP addresses or host name that you want to resolve, or alternatively, you can specify IP addresses range that you want to scan. For local network, FastResolver also allows you to get the MAC address of all IP addresses that you scan. FastResolver is a multithreaded application, so it can resolve dozens of addresses within a few seconds.

<<less
Download (36.32KB)
Added: 2008-10-30 License: Freeware Price:
408 downloads
 
Other version of FastResolver
FastResolver 1.20Nir Sofer - It resolves multiple host names into IP addresses and vice versa. FastResolver. FastResolver is a small utility that resolves
License:Freeware
Download (36KB)
490 downloads
Added: 2008-08-13
FastResolver 1.00NirSoft Freeware - Resolves multiple host names into IP addresses and vice versa. FastResolver. FastResolver is a small utility that resolves
License:Freeware
Download (35KB)
1530 downloads
Added: 2005-10-08
Digi-Link Resolve 1.1

Digi-Link Resolve 1.1


automatically browse web sites offline, use links in Outlook email more>> Resolve will let users click on email links and browse web sites offline, automatically. Resolve handles links in Outlook emails, even unread emails. Resolve works with Web sites, web documents, PDFs, word etc. resolve works with Microsoft SharePoint.
Users get newsletters, maps, documents, company info in emails. Now you can browse the web site on a plane, train or anywhere.
fast full text search of email and attachments with no adware. There are no links back in this fast full text search product.
Choose to see just web sites from your contacts or download everything.
<<less
Download (8.2M)
Added: 2008-10-30 License: Commercial Price: $20.00user,$300unlimited
362 downloads
Resolve for Enfal 1.07

Resolve for Enfal 1.07


A tool that removes Enfal trojan more>> A tool that removes Enfal trojan

Resolve is the name for a set of small, downloadable Sophos utilities designed to remove and undo the changes made by certain viruses, Trojans and worms. They terminate any virus processes and reset any registry keys that the virus changed. Existing infections can be cleaned up quickly and easily, both on individual workstations and over networks with large numbers of computers.
Troj/Enfal-A is a Trojan for the Windows platform.
Troj/Enfal-A includes functionality to:
- inject multiple threads into the process EXPLORER.EXE
- download code from the internet
When run Troj/Enfal-A copies itself to dismgnt.exe and winkrnl.exe.
Troj/Enfal-A modifies the following registry entry to run itself on Windows Logon:
HKLMSOFTWAREMicrosoftWindows NTCurrentVersionWinlogon
Userinit
userinit.exe,DisMgnt.exe
Troj/Enfal-B is a backdoor Trojan for the Windows platform.
Troj/Enfal-B includes functionality to access the internet and communicate with a remote server via HTTP.
When Troj/Enfal-B is installed the following files are created:
DisMgnt.exe
NtApi.exe
Winkrnl.exe
acetempkb791024.l0g
where NtApi.exe is an archiver application.
Troj/Enfal-B injects multiple threads into the process EXPLORER.EXE.
The files DisMgnt.exe and Winkrnl.exe are detected as Troj/Enfal-A.
Registry entries are set as follows:
HKCUSoftwareMicrosoftWindowsCurrentVersionExplorerAdvanced
ShowSuperHidden
0
HKLMSOFTWAREMicrosoftWindows NTCurrentVersionWinlogon
Shell
Explorer.exe,
Windows disinfector
BDLAAGUI is a disinfector for standalone Windows computers. To use it you have to do the following:
- Open BDLAAGUI.com file from your desktop after downloading it.
- Click on the Start Scan Button.
- Wait for the process to complete.
Command line disinfector
ENFALSFX.EXE is a self-extracting archive containing ENFALCLI, a Resolve command line disinfector for use by system administrators on Windows networks.

<<less
Download (78KB)
Added: 2008-09-23 License: Freeware Price: FREE
478 downloads
Resolve for Stinx 1.07

Resolve for Stinx 1.07


A tool that removes Stinx trojan more>> A tool that removes Stinx trojan

Resolve is the name for a set of small, downloadable Sophos utilities designed to remove and undo the changes made by certain viruses, Trojans and worms. They terminate any virus processes and reset any registry keys that the virus changed.
Existing infections can be cleaned up quickly and easily, both on individual workstations and over networks with large numbers of computers.
Troj/Stinx-Q is an IRC backdoor Trojan for the Windows platform.
The Trojan may arrive as an email attachment with the filename "Photo+Article.zip".
When first run Troj/Stinx-Q copies itself to csrnvrt.exe and creates two randomly named BAT files in the Temp folder. One of these files is used to attempt to bypass the Windows firewall. The other is used to delete the original copy of the Trojan. Troj/Stinx-Q is an IRC backdoor Trojan for the Windows platform.
The Trojan may arrive as an email attachment with the filename "Photo+Article.zip". Typically the email has characteristics similar to the following:
Subject line:
Photo and Article
Message text:
Hello,
Your photograph has reached editing stage as part of an article we are publishing for our February edition of Traders World Monthly. Can you check over the format and get back to us with your approval or any changes?
If the picture is not to your liking then please send a preferred one. Weve attached the photo with the article here.
Troj/Stinx-Q connects to an IRC channel and listens for backdoor commands from a remote user. Backdoor functionality includes the ability to run arbitrary commands.
The Trojan may also download further malicious code.
Troj/Stinx-Q attempts to terminate a number of processes, including some belonging to anti-virus applications.
When first run Troj/Stinx-Q copies itself to csrnvrt.exe and creates two randomly named BAT files in the Temp folder. One of these files is used to attempt to bypass the Windows firewall. The other is used to delete the original copy of the Trojan.
The following registry entries are created to run csrnvrt.exe on startup:
HKCUSoftwareMicrosoftWindowsCurrentVersionRun
DriverModule
csrnvrt.exe
HKLMSOFTWAREMicrosoftWindowsCurrentVersionRun
DriverModule
csrnvrt.exe
Troj/Stinx-R is a backdoor Trojan for the Windows platform.
The Trojan connects to an IRC server and joins a predetermined channel. The Trojan then accepts commands from remote attackers. Troj/Stinx-R is a backdoor Trojan for the Windows platform.
When first run Troj/Stinx-R copies itself to csrnvrt.exe and creates two randomly named BAT files in the Temp folder. One of these files is used to attempt to bypass the Windows firewall. The other is used to delete the original copy of the Trojan.
The following registry entries are created to run csrnvrt.exe on startup:
HKCUSoftwareMicrosoftWindowsCurrentVersionRun
DriverModule
csrnvrt.exe
HKLMSOFTWAREMicrosoftWindowsCurrentVersionRun
DriverModule
csrnvrt.exe
The Trojan connects to an IRC server and joins a predetermined channel. The Trojan then accepts commands from remote attackers.
The Trojan may also download further malicious code.
Troj/Stinx-R attempts to terminate a number of processes, including some belonging to anti-virus applications.
Troj/Stinx-S is a backdoor Trojan for the Windows platform.
Troj/Stinx-S connects to a number of remote ip addresses on port 8080, providing a backdoor server which allows a remote intruder to gain access and control over the computer.
When first run Troj/Stinx-S copies itself to lsadst.exe and creates the following registry entries to run this file on startup:
HKCUSoftwareMicrosoftWindowsCurrentVersionRun
WindowsProtocolLog
lsadst.exe
HKLMSOFTWAREMicrosoftWindowsCurrentVersionRun
WindowsProtocolLog
lsadst.exe
Troj/Stinx-S may drop and run files called .bat in order to bypass the Windows firewall using "netsh" or in order to delete itself.
Troj/Stinx-S attempts to terminate a number of processes related to anti-virus and security programs.
Troj/Stinx-S may download and execute files from a remote website.
Troj/Stinx-U is a backdoor Trojan for the Windows platform.
Troj/Stinx-U connects to a number of remote ip addresses on port 8080, providing a backdoor server which allows a remote intruder to gain access and control over the computer.
Troj/Stinx-U attempts to terminate a number of processes related to anti-virus and security programs.
Troj/Stinx-U may download and execute files from a remote website. Troj/Stinx-U is a backdoor Trojan for the Windows platform.
Troj/Stinx-U connects to a number of remote ip addresses on port 8080, providing a backdoor server which allows a remote intruder to gain access and control over the computer.
When first run Troj/Stinx-U copies itself to lsadst.exe and creates the following registry entries to run this file on startup:
HKCUSoftwareMicrosoftWindowsCurrentVersionRun
WindowsDiskEvt
svcsvh32.exe
HKLMSOFTWAREMicrosoftWindowsCurrentVersionRun
WindowsDiskEvt
svcsvh32.exe
Troj/Stinx-U may drop and run files called .bat in order to bypass the Windows firewall using "netsh" or in order to delete itself.
Troj/Stinx-U attempts to terminate a number of processes related to anti-virus and security programs.
Troj/Stinx-U may download and execute files from a remote website.
Troj/Stinx-Q, Troj/Stinx-R, Troj/Stinx-S and Troj/Stinx-U can be removed from Windows computers automatically with the following Resolve tools:
Windows disinfector
STINXGUI is a disinfector for standalone Windows computers. To use it you have to do the following:
- Open STINXGUI.com file from your desktop after downloading it.
- Click on the Start Scan Button.
- Wait for the process to complete.
Command line disinfector
STINXSFX.EXE is a self-extracting archive containing STINXCLI, a Resolve command line disinfector for use by system administrators on Windows networks.

<<less
Download (86KB)
Added: 2008-09-23 License: Freeware Price: FREE
398 downloads
Resolve for Agobot 1.07

Resolve for Agobot 1.07


A tool that removes W32 Agobot more>> A tool that removes W32 Agobot

Resolve is the name for a set of small, downloadable Sophos utilities designed to remove and undo the changes made by certain viruses, Trojans and worms. They terminate any virus processes and reset any registry keys that the virus changed.
Existing infections can be cleaned up quickly and easily, both on individual workstations and over networks with large numbers of computers.
W32/Agobot-BT is a network worm which also allows unauthorised remote access to the computer via IRC channels.
W32/Agobot-BT copies itself to network shares with weak passwords and attempts to spread to computers using the DCOM RPC and the RPC locator vulnerabilities.
These vulnerabilities allow the worm to execute its code on target computers with System level privileges. For further information on these vulnerabilities and for details on how to protect/patch the computer against such attacks please see Microsoft security bulletins MS03-001 and MS03-026. MS03-026 has been superseded by Microsoft security bulletin MS03-039.
W32/Agobot-BT copies itself to the Windows system folder as sysinfo.exe and creates the following registry entries to run itself on system restart:
HKLMSoftwareMicrosoftWindowsCurrentVersionRun
Configuration Loader
HKLMSoftwareMicrosoftWindowsCurrentVersionRunServices
Configuration Loader
Each time W32/Agobot-BT is run it attempts to connect to a remote IRC server and join a specific channel.
W32/Agobot-BT attempts to terminate various processes related to anti-virus and security software (e.g. SWEEP95.EXE, BLACKICE.EXE and ZONEALARM.EXE).
W32/Agobot-BT, W32/Agobot-HD, W32/Agobot-HH, W32/Agobot-HL, W32/Agobot-HS, W32/Agobot-IJ, W32/Agobot-IK, W32/Agobot-LG, W32/Agobot-LT, W32/Agobot-MR, W32/Agobot-MW, W32/Agobot-NA, W32/Agobot-NZ, W32/Agobot-OT, W32/Agobot-OU, W32/Agobot-QF, W32/Agobot-QO,
Windows disinfector
AGOBTGUI is a disinfector for standalone Windows computers. To use it you have to do the following:
- Open AGOBTGUI.com file from your desktop after downloading it.
- Click on the Start Scan Button.
- Wait for the process to complete.
Command line disinfector
AGOBTSFX.EXE is a self-extracting archive containing AGOBTCLI, a Resolve command line disinfector for use by system administrators on Windows networks.
After removing the worm you should check the virus analysis for details of any Microsoft security updates you should make, or, on single computers, update with all relevant security patches from Windows update.
For W32/Agobot-HH, W32/Agobot-LT, W32/Agobot-NZ, W32/Agobot-OT, W32/Agobot-OU and W32/Agobot-SX you should replace the HOSTS file from backup, or open it in Notepad and remove any of the entries listed in the virus description.

<<less
Download (144KB)
Added: 2008-09-23 License: Freeware Price: FREE
457 downloads
Resolve for Dloader 1.07

Resolve for Dloader 1.07


A tool that removes Dloader trojan more>> A tool that removes Dloader trojan

Resolve is the name for a set of small, downloadable Sophos utilities designed to remove and undo the changes made by certain viruses, Trojans and worms. They terminate any virus processes and reset any registry keys that the virus changed. Existing infections can be cleaned up quickly and easily, both on individual workstations and over networks with large numbers of computers.
Troj/Dloader-ML is a downloading Trojan for the Windows platform.
Once executed Troj/Dloader-ML copies itself to the Windows system folder with a random filename and runs the copy.
Troj/Dloader-ML injects code into new hidden instances of explorer.exe, winlogon.exe and packager.exe.
These processes prevent each other from being terminated.
Troj/Dloader can be removed from Windows computers automatically with the following Resolve tools:
Windows disinfector
DLOADGUI is a disinfector for standalone Windows computers. To use it you have to do the following:
- Open DLOADGUI.com file from your desktop after downloading it.
- Click on the Start Scan Button.
- Wait for the process to complete.
Command line disinfector
DLOADSFX.EXE is a self-extracting archive containing DLOADCLI, a Resolve command line disinfector for use by system administrators on Windows networks.

<<less
Download (78KB)
Added: 2008-09-23 License: Freeware Price: FREE
413 downloads
Resolve for Startpa 1.06

Resolve for Startpa 1.06


A tool that removes Startpa trojan more>> A tool that removes Startpa trojan

Resolve is the name for a set of small, downloadable Sophos utilities designed to remove and undo the changes made by certain viruses, Trojans and worms. They terminate any virus processes and reset any registry keys that the virus changed.
Existing infections can be cleaned up quickly and easily, both on individual workstations and over networks with large numbers of computers.
Troj/StartPa-I attempts to modify several Microsoft Internet Explorer values.
Troj/StartPa-I drops a DLL component to the System folder as ctrlpan.dll (also detected as Troj/StartPa-I) and adds the following registry entry in order to run this component on system restart:
HKLMSoftwareMicrosoftWindows NTCurrentVersion
WindowsAppInit_DLLs = "ctrlpan.dll"
Troj/StartPa-I sets the following registry entries relating to Internet Explorer to http://aifind.info/:
HKCUSoftwareMicrosoftInternet ExplorerSearchURL HKCUSoftwareMicrosoftInternet ExplorerMainSearch Page HKCUSoftwareMicrosoftInternet ExplorerMainStart Page HKCUSoftwareMicrosoftInternet ExplorerMainSearch Bar HKLMSoftwareMicrosoftInternet ExplorerSearch
Troj/StartPa-I creates or overwrites C:\driversetchosts, which has the following entries:
127.0.0.1 localhost
205.177.124.66 auto.search.msn.com
Troj/StartPa-I creates an HTML stylesheet in C:hh.htt and creates associated registry entries in
HKLMSoftwareMicrosoftInternet ExplorerStylesUser Stylesheet and
HKLMSoftwareMicrosoftInternet ExplorerStylesUse My Stylesheet.
The URL files will have links to porn-related websites.
Troj/Startpa-Z is a simple Trojan that makes changes to Internet Explorer settings via the registry.
Troj/Startpa-Z changes the default start page of Internet Explorer to the URL http://aifind.info/ and will add a list of URLs containg adult content to the favourites folder. The Trojan will also change the following registry entries:
HKCUSoftwareMicrosoftInternet ExplorerStyles
Use My Stylesheet = 1
HKCUSoftwareMicrosoftInternet ExplorerStyles
User Stylesheet = hh.htt
HKLMSoftwareMicrosoftInternet ExplorerStyles
Use My Stylesheet = 1
HKLMSoftwareMicrosoftInternet ExplorerStyles
User Stylesheet = hh.htt
The stylesheet file hh.htt is detected by Sophos Anti-Virus as Troj/Startpa-BG.
Troj/Startpa can be removed from Windows computers automatically with the following Resolve tools:
Windows disinfector
STRTPGUI is a disinfector for standalone Windows computers. To use it you have to do the following:
- Open STRTPGUI.com file from your desktop after downloading it.
- Click on the Start Scan Button.
- Wait for the process to complete.
Command line disinfector
STRTPSFX.EXE is a self-extracting archive containing STRTPCLI, a Resolve command line disinfector for use by system administrators on Windows networks.

<<less
Download (77KB)
Added: 2008-09-23 License: Freeware Price: FREE
395 downloads
Resolve for Alcra-B 1.07

Resolve for Alcra-B 1.07


A tool that removes W32/Alcra-B more>> A tool that removes W32/Alcra-B

Resolve is the name for a set of small, downloadable Sophos utilities designed to remove and undo the changes made by certain viruses, Trojans and worms.
They terminate any virus processes and reset any registry keys that the virus changed. Existing infections can be cleaned up quickly and easily, both on individual workstations and over networks with large numbers of computers.
W32/Alcra-B is a worm for the Windows platform.
W32/Alcra-B spreads via file sharing on P2P networks.
W32/Alcra-B includes functionality to download, install and run new malware executables. W32/Alcra-B is a worm for the Windows platform.
W32/Alcra-B spreads via file sharing on P2P networks.
W32/Alcra-B includes functionality to download, install and run new malware executables.
W32/Alcra-B typically arrives with the filename Setup.exe.
When first run W32/Alcra-B displays a dialog box with the text "Setup", "Welcome to the Setup Wizard ...". W32/Alcra-B creates the folder winupdates, copies itself to this folder as winupdates.exe and creates the following files:
winupdatesa.zip
cmd.com
bszip.dll
netstat.com
ping.com
regedit.com
taskkill.com
tasklist.com
tracert.com
All files and folders will have the hidden and system attributes set, including the Windows system folder.
a.zip is a zip archive containing a copy of W32/Alcra-B named Setup.exe.
Bszip.dll is a clean file compression utility.
The new files created in the Windows system folder by W32/Alcra-B with a COM extension are simply MZ stubs (2-byte files simply containing "MZ"), designed to disable the standard Windows applications: cmd, netstat, ping, regedit, taskkill, tasklist and tracert. Executables files with a COM extension have precedence over files with the same filename, but an extension of EXE, therefore if a user runs "cmd", "netstat", "ping", "regedit", "taskkill", "tasklist" or "tracert", the new file with a COM extension will be executed rather than the legitimate executable with an extension of EXE.
The following registry entry is created to run winupdates.exe on startup:
HKLMSOFTWAREMicrosoftWindowsCurrentVersionRun
winupdates
winupdateswinupdates.exe /auto
W32/Alcra-B can be removed from Windows computers automatically with the following Resolve tools:
Windows disinfector
ALCRAGUI is a disinfector for standalone Windows computers. To use it you have to do the following:
- Open ALCRAGUI.com file from your desktop after downloading it.
- Click on the Start Scan Button.
- Wait for the process to complete.
Command line disinfector
ALCRASFX.EXE is a self-extracting archive containing ALCRACLI, a Resolve command line disinfector for use by system administrators on Windows networks.

<<less
Download (76KB)
Added: 2008-09-23 License: Freeware Price: FREE
401 downloads
Resolve for Banker-R 1.06

Resolve for Banker-R 1.06


A tool that removes Banker-R trojan more>> A tool that removes Banker-R trojan

Resolve is the name for a set of small, downloadable Sophos utilities designed to remove and undo the changes made by certain viruses, Trojans and worms.
They terminate any virus processes and reset any registry keys that the virus changed. Existing infections can be cleaned up quickly and easily, both on individual workstations and over networks with large numbers of computers.
Troj/Banker-R can be removed from Windows computers automatically with the following Resolve tools:
Windows disinfector
BDLAAGUI is a disinfector for standalone Windows computers. To use it you have to do the following:
- Open BANKRGUI.com file from your desktop after downloading it.
- Click on the Start Scan Button.
- Wait for the process to complete.
Command line disinfector
BANKRSFX.EXE is a self-extracting archive containing BANKRCLI, a Resolve command line disinfector for use by system administrators on Windows networks.

<<less
Download (79KB)
Added: 2008-09-23 License: Freeware Price: FREE
398 downloads
Resolve for Surila-E 1.07

Resolve for Surila-E 1.07


A tool that remove Surila-E trojan more>> A tool that remove Surila-E trojan

Resolve is the name for a set of small, downloadable Sophos utilities designed to remove and undo the changes made by certain viruses, Trojans and worms. They terminate any virus processes and reset any registry keys that the virus changed.
Existing infections can be cleaned up quickly and easily, both on individual workstations and over networks with large numbers of computers.
Troj/Surila-E is a backdoor Trojan which allows a remote intruder to gain access and control over the computer.
Troj/Surila-E includes functionality to access the internet and communicate with a remote server via HTTP.
When first run Troj/Surila-E copies itself to:
csrss.exe
msupdate.exe
and creates a file dodrrr.exe detected as Troj/Surila-D.
Troj/Surila-E modifies the system file sfc_os.dll in an attempt to disable the Windows System File Checker. The Trojan may do this in order to modify further system files.
The following registry entries are created to run msupdate.exe on startup:
HKCUSoftwareMicrosoftWindowsCurrentVersionRun
msupdate
msupdate.exe
HKLMSOFTWAREMicrosoftWindowsCurrentVersionRun
msupdate
msupdate.exe
HKLMSOFTWAREMicrosoftWindowsCurrentVersionRunOnce
msupdate
msupdate.exe
Registry entries are set as follows:
HKCUSoftwareMicrosoftInternet Explorer
mtxqwnm
nVKHFQU
HKCUSoftwareMicrosoftInternet Explorer
veer
40040
HKCUSoftwareMicrosoftWindowsCurrentVersionPolicies
DisableRegistryTools
0
HKLMSOFTWAREMicrosoftWindowsCurrentVersionpolicies
DisableRegistryTools
0
HKLMSOFTWAREMicrosoftOle
WINRUN
msupdate.exe
HKLMSOFTWAREMicrosoftWindows NTCurrentVersionWinlogon
SFCScan
0
HKLMSYSTEMCurrentControlSetControlLsa
WINRUN
msupdate.exe
HKLMSOFTWAREMicrosoftWindows NTCurrentVersionWinlogon
SFCDisable
ffffff9d
Troj/Surila-E can be removed from Windows computers automatically with the following Resolve tools:
Windows disinfector
SURILGUI is a disinfector for standalone Windows computers. To use it you have to do the following:
- Open SURILGUI.com file from your desktop after downloading it.
- Click on the Start Scan Button.
- Wait for the process to complete.
Command line disinfector
SURILSFX.EXE is a self-extracting archive containing SURILCLI, a Resolve command line disinfector for use by system administrators on Windows networks.

<<less
Download (77KB)
Added: 2008-09-23 License: Freeware Price: FREE
415 downloads
Resolve for Daoser-C 1.07

Resolve for Daoser-C 1.07


A tool that removes Daoser-C trojan more>> A tool that removes Daoser-C trojan

Resolve is the name for a set of small, downloadable Sophos utilities designed to remove and undo the changes made by certain viruses, Trojans and worms. They terminate any virus processes and reset any registry keys that the virus changed. Existing infections can be cleaned up quickly and easily, both on individual workstations and over networks with large numbers of computers.
Troj/Daoser-C is a Trojan for the Windows platform.
Troj/Daoser-C will modify the start page for Internet Explorer.
Troj/Daoser-C may display popups and spy on web searches and browsing habits. Troj/Daoser-C is a Trojan for the Windows platform.
Troj/Daoser-C will modify the start page for Internet Explorer.
Troj/Daoser-C may display popups and spy on web searches and browsing habits.
When the Trojan is installed the following files are created:
ServicesSVCHOST32.DLL
Servicessecurity.exe
Servicessvchost.dll
Servicessvchost.exe
where is a string of letters and numbers.
The following registry entry is created to run svchost.exe on startup:
HKLMSOFTWAREMicrosoftWindowsCurrentVersionRun
Service Host
ServicesSVCHOST.EXE
The Trojan changes the Start Page for Microsoft Internet Explorer by altering the registry entry:
HKCUSoftwareMicrosoftInternet ExplorerMainStart Page
Troj/Daoser-C can be removed from Windows computers automatically with the following Resolve tools:
Windows disinfector
DAOSRGUI is a disinfector for standalone Windows computers. To use it you have to do the following:
- Open DAOSRGUI.com file from your desktop after downloading it.
- Click on the Start Scan Button.
- Wait for the process to complete.
Command line disinfector
DAOSRSFX.EXE is a self-extracting archive containing DAOSRCLI, a Resolve command line disinfector for use by system administrators on Windows networks.

<<less
Download (85KB)
Added: 2008-09-23 License: Freeware Price: FREE
403 downloads
Resolve for Delf-ALI 1.07

Resolve for Delf-ALI 1.07


A tool that removes Delf-ALI trojan more>> A tool that removes Delf-ALI trojan

Resolve is the name for a set of small, downloadable Sophos utilities designed to remove and undo the changes made by certain viruses, Trojans and worms. They terminate any virus processes and reset any registry keys that the virus changed. Existing infections can be cleaned up quickly and easily, both on individual workstations and over networks with large numbers of computers.
Troj/Delf-ALI is a worm and IRC backdoor Trojan for the Windows platform.
Troj/Delf-ALI spreads to other network computers by exploiting common buffer overflow vulnerabilities, including RPC-DCOM (MS04-012).
Troj/Delf-ALI runs continuously in the background, providing a backdoor server which allows a remote intruder to gain access and control over the computer via IRC channels.
Troj/Delf-ALI includes functionality to access the internet and communicate with a remote server via HTTP.
When Troj/Delf-ALI is installed it creates the clean text file msguid32.dll.
The following registry entry is created to run Troj/Delf-ALI on startup:
HKLMSOFTWAREMicrosoftWindowsCurrentVersionRun
Microsoft IIS
Troj/Delf-ALI attempts to log details from banking applications related to the following sites:
www.halifax-online.co.uk
ibank.barclays.co.uk
online.lloydstsb.co.uk
online-business.lloydstsb.co.uk
www.ukpersonal.hsbc.co.uk
banesnet.banesto.es
extranet.banesto.es
ebanking.bccbrescia.it
www.bankofscotlandhalifax-online.co.uk
oi.cajamadrid.es
bancae.caixapenedes.com
banking.postbank.de
meine.deutsche-bank.de
myonlineaccounts2.abbeynational.co.uk
ibank.cahoot.com
webbank.openplan.co.uk
bancopostaonline.poste.it
mybank.bybank.it
ibank.internationalbanking.barclays.com
welcome7.co-operativebank.co.uk
welcome11.co-operativebankonline.co.uk
Troj/Delf-ALI modifies the HOSTS file in order to redirect access to the above sites.
Troj/Delf-ALI stores logged information to the following clean text files in the Windows system folder:
abbey.dll
bane.dll
bankofscot.dll
barc.dll
barc3.dll
bccbrescia.dll
bybank.dll
cahoot.dll
caixapenedes.dll
cajamadrid.dll
coo11.dll
coo7.dll
deutchebank.dll
halif.dll
hsbc.dll
lloy.dll
posta.dll
postbank.dll
wool.dll
Troj/Delf-ALI can be removed from Windows computers automatically with the following Resolve tools:
Windows disinfector
DELFAGUI is a disinfector for standalone Windows computers. To use it you have to do the following:
- Open DELFAGUI.com file from your desktop after downloading it.
- Click on the Start Scan Button.
- Wait for the process to complete.
- After removing the worm you should install the Microsoft patch MS04-012 or, on single computers, update with all relevant security patches from Windows update.
Command line disinfector
DELFASFX.EXE is a self-extracting archive containing DELFACLI, a Resolve command line disinfector for use by system administrators on Windows networks.

<<less
Download (76KB)
Added: 2008-09-23 License: Freeware Price: FREE
396 downloads
Resolve for W32/Anig 1.06

Resolve for W32/Anig 1.06


A tool that removes W32/Anig more>> A tool that removes W32/Anig

Resolve is the name for a set of small, downloadable Sophos utilities designed to remove and undo the changes made by certain viruses, Trojans and worms.
They terminate any virus processes and reset any registry keys that the virus changed. Existing infections can be cleaned up quickly and easily, both on individual workstations and over networks with large numbers of computers.
W32/Anig-A is a worm that can spread by copying itself over network shares.
W32/Anig-A can also be used to steal passwords.
W32/Anig-A copies itself to System32 using its original filename and
creates the following registry entry in order to run on system restart:
HKLMSoftwareMicrosoftWindowsCurrentVersionRunOsa32
W32/Anig-A attempts to spread by copying itself to the share ADMIN$ on remote
machines.
W32/Anig-A may drop a DLL file with keylogging functionality called GinaDLL.DLL
and open port 5190 in order to receive remote commands.
W32/Anig-A registers itself as a service called Distributed File Controller
by creating the following registry entries:
HKLMSystemCurrentControlSetServicesdfcsvc
DependOnGroup = ""
DependOnService = RpcSS
DisplayName = Distributed File Controller
Error Control = 0x0
ImagePath = /dfcsvc
ObjectName = LocalSystem
Start = 0x2
Type = 0x110
W32/Anig-A may also create the following registry entries:
HKLMSoftwareMicrosoftWindows NTCurrentVersionWinlogon
GinaDll = ntgina.dll
Ram32Data
Ram32ID
Ram32Group
W32/Anig-C is a worm that can spread by copying itself over network shares.
W32/Anig-C can also be used to steal passwords.
W32/Anig-C attempts to spread by copying itself to the share ADMIN$ on remote computers.
W32/Anig-C may drop a DLL file with keylogging functionality called GinaDLL.DLL and open port 5190 in order to receive remote commands. W32/Anig-C is a worm that can spread by copying itself over network shares.
W32/Anig-C can also be used to steal passwords.
W32/Anig-C copies itself to System32 using its original filename and creates the following registry entry in order to run on system restart:
HKLMSoftwareMicrosoftWindowsCurrentVersionRunOsa32
W32/Anig-C attempts to spread by copying itself to the share ADMIN$ on remote computers.
W32/Anig-C may drop a DLL file with keylogging functionality called GinaDLL.DLL and open port 5190 in order to receive remote commands.
On NT based versions of Windows, W32/Anig-C registers itself as a service called with the display name Distributed File Controller. The new service has a Startup type of automatic so that the service is started automatically each time a new Windows session is started. New registry entries are created beneath the following registry entry:
HKLMSystemCurrentControlSetServicesdfcsvc
W32/Anig-C may also create the following registry entry:
HKLMSoftwareMicrosoftWindows NTCurrentVersionWinlogon
GinaDll
ntgina.dll
W32/Anig can be removed from Windows computers automatically with the following Resolve tools:
Windows disinfector
ANIGGUI is a disinfector for standalone Windows computers. To use it you have to do the following:
- Open ANIGGUI.com file from your desktop after downloading it.
- Click on the Start Scan Button.
- Wait for the process to complete.
Command line disinfector
ANIGSFX.EXE is a self-extracting archive containing ANIGCLI, a Resolve command line disinfector for use by system administrators on Windows networks.

<<less
Download (75KB)
Added: 2008-09-23 License: Freeware Price: FREE
396 downloads
Secleted [ 0 ] software to compare
  • Page: 1 of 5
  • 1
  • 2
  • 3
  • 4
  • 5