to resolve
FastResolver 1.22
FastResolver is a small utility that resolves multiple host names into IP addresses/MAC Addresses and vice versa. more>>
FastResolver is a small utility that resolves multiple host names into IP addresses and vice versa. You can simply type the list of IP addresses or host name that you want to resolve, or alternatively, you can specify IP addresses range that you want to scan. For local network, FastResolver also allows you to get the MAC address of all IP addresses that you scan. FastResolver is a multithreaded application, so it can resolve dozens of addresses within a few seconds.
<<less
You can simply type the list of IP addresses or host name that you want to resolve, or alternatively, you can specify IP addresses range that you want to scan. For local network, FastResolver alsoDigi-Link Resolve 1.1
automatically browse web sites offline, use links in Outlook email more>> Resolve will let users click on email links and browse web sites offline, automatically. Resolve handles links in Outlook emails, even unread emails. Resolve works with Web sites, web documents, PDFs, word etc. resolve works with Microsoft SharePoint.
Users get newsletters, maps, documents, company info in emails. Now you can browse the web site on a plane, train or anywhere.
fast full text search of email and attachments with no adware. There are no links back in this fast full text search product.
Choose to see just web sites from your contacts or download everything.<<less
IpDnsResolver 1.2
IpDnsResolver lets you find your IP address, resolve hostnames to IP addresses using the DNS more>>
Resolve for Enfal 1.07
A tool that removes Enfal trojan more>> A tool that removes Enfal trojan
Resolve is the name for a set of small, downloadable Sophos utilities designed to remove and undo the changes made by certain viruses, Trojans and worms. They terminate any virus processes and reset any registry keys that the virus changed. Existing infections can be cleaned up quickly and easily, both on individual workstations and over networks with large numbers of computers.
Troj/Enfal-A is a Trojan for the Windows platform.
Troj/Enfal-A includes functionality to:
- inject multiple threads into the process EXPLORER.EXE
- download code from the internet
When run Troj/Enfal-A copies itself to dismgnt.exe and winkrnl.exe.
Troj/Enfal-A modifies the following registry entry to run itself on Windows Logon:
HKLMSOFTWAREMicrosoftWindows NTCurrentVersionWinlogon
Userinit
userinit.exe,DisMgnt.exe
Troj/Enfal-B is a backdoor Trojan for the Windows platform.
Troj/Enfal-B includes functionality to access the internet and communicate with a remote server via HTTP.
When Troj/Enfal-B is installed the following files are created:
DisMgnt.exe
NtApi.exe
Winkrnl.exe
acetempkb791024.l0g
where NtApi.exe is an archiver application.
Troj/Enfal-B injects multiple threads into the process EXPLORER.EXE.
The files DisMgnt.exe and Winkrnl.exe are detected as Troj/Enfal-A.
Registry entries are set as follows:
HKCUSoftwareMicrosoftWindowsCurrentVersionExplorerAdvanced
ShowSuperHidden
0
HKLMSOFTWAREMicrosoftWindows NTCurrentVersionWinlogon
Shell
Explorer.exe,
Windows disinfector
BDLAAGUI is a disinfector for standalone Windows computers. To use it you have to do the following:
- Open BDLAAGUI.com file from your desktop after downloading it.
- Click on the Start Scan Button.
- Wait for the process to complete.
Command line disinfector
ENFALSFX.EXE is a self-extracting archive containing ENFALCLI, a Resolve command line disinfector for use by system administrators on Windows networks.
Resolve for Agobot 1.07
A tool that removes W32 Agobot more>> A tool that removes W32 Agobot
Resolve is the name for a set of small, downloadable Sophos utilities designed to remove and undo the changes made by certain viruses, Trojans and worms. They terminate any virus processes and reset any registry keys that the virus changed.
Existing infections can be cleaned up quickly and easily, both on individual workstations and over networks with large numbers of computers.
W32/Agobot-BT is a network worm which also allows unauthorised remote access to the computer via IRC channels.
W32/Agobot-BT copies itself to network shares with weak passwords and attempts to spread to computers using the DCOM RPC and the RPC locator vulnerabilities.
These vulnerabilities allow the worm to execute its code on target computers with System level privileges. For further information on these vulnerabilities and for details on how to protect/patch the computer against such attacks please see Microsoft security bulletins MS03-001 and MS03-026. MS03-026 has been superseded by Microsoft security bulletin MS03-039.
W32/Agobot-BT copies itself to the Windows system folder as sysinfo.exe and creates the following registry entries to run itself on system restart:
HKLMSoftwareMicrosoftWindowsCurrentVersionRun
Configuration Loader
HKLMSoftwareMicrosoftWindowsCurrentVersionRunServices
Configuration Loader
Each time W32/Agobot-BT is run it attempts to connect to a remote IRC server and join a specific channel.
W32/Agobot-BT attempts to terminate various processes related to anti-virus and security software (e.g. SWEEP95.EXE, BLACKICE.EXE and ZONEALARM.EXE).
W32/Agobot-BT, W32/Agobot-HD, W32/Agobot-HH, W32/Agobot-HL, W32/Agobot-HS, W32/Agobot-IJ, W32/Agobot-IK, W32/Agobot-LG, W32/Agobot-LT, W32/Agobot-MR, W32/Agobot-MW, W32/Agobot-NA, W32/Agobot-NZ, W32/Agobot-OT, W32/Agobot-OU, W32/Agobot-QF, W32/Agobot-QO,
Windows disinfector
AGOBTGUI is a disinfector for standalone Windows computers. To use it you have to do the following:
- Open AGOBTGUI.com file from your desktop after downloading it.
- Click on the Start Scan Button.
- Wait for the process to complete.
Command line disinfector
AGOBTSFX.EXE is a self-extracting archive containing AGOBTCLI, a Resolve command line disinfector for use by system administrators on Windows networks.
After removing the worm you should check the virus analysis for details of any Microsoft security updates you should make, or, on single computers, update with all relevant security patches from Windows update.
For W32/Agobot-HH, W32/Agobot-LT, W32/Agobot-NZ, W32/Agobot-OT, W32/Agobot-OU and W32/Agobot-SX you should replace the HOSTS file from backup, or open it in Notepad and remove any of the entries listed in the virus description.
Resolve for Dloader 1.07
A tool that removes Dloader trojan more>> A tool that removes Dloader trojan
Resolve is the name for a set of small, downloadable Sophos utilities designed to remove and undo the changes made by certain viruses, Trojans and worms. They terminate any virus processes and reset any registry keys that the virus changed. Existing infections can be cleaned up quickly and easily, both on individual workstations and over networks with large numbers of computers.
Troj/Dloader-ML is a downloading Trojan for the Windows platform.
Once executed Troj/Dloader-ML copies itself to the Windows system folder with a random filename and runs the copy.
Troj/Dloader-ML injects code into new hidden instances of explorer.exe, winlogon.exe and packager.exe.
These processes prevent each other from being terminated.
Troj/Dloader can be removed from Windows computers automatically with the following Resolve tools:
Windows disinfector
DLOADGUI is a disinfector for standalone Windows computers. To use it you have to do the following:
- Open DLOADGUI.com file from your desktop after downloading it.
- Click on the Start Scan Button.
- Wait for the process to complete.
Command line disinfector
DLOADSFX.EXE is a self-extracting archive containing DLOADCLI, a Resolve command line disinfector for use by system administrators on Windows networks.
Resolve for Startpa 1.06
A tool that removes Startpa trojan more>> A tool that removes Startpa trojan
Resolve is the name for a set of small, downloadable Sophos utilities designed to remove and undo the changes made by certain viruses, Trojans and worms. They terminate any virus processes and reset any registry keys that the virus changed.
Existing infections can be cleaned up quickly and easily, both on individual workstations and over networks with large numbers of computers.
Troj/StartPa-I attempts to modify several Microsoft Internet Explorer values.
Troj/StartPa-I drops a DLL component to the System folder as ctrlpan.dll (also detected as Troj/StartPa-I) and adds the following registry entry in order to run this component on system restart:
HKLMSoftwareMicrosoftWindows NTCurrentVersion
WindowsAppInit_DLLs = "ctrlpan.dll"
Troj/StartPa-I sets the following registry entries relating to Internet Explorer to http://aifind.info/:
HKCUSoftwareMicrosoftInternet ExplorerSearchURL HKCUSoftwareMicrosoftInternet ExplorerMainSearch Page HKCUSoftwareMicrosoftInternet ExplorerMainStart Page HKCUSoftwareMicrosoftInternet ExplorerMainSearch Bar HKLMSoftwareMicrosoftInternet ExplorerSearch
Troj/StartPa-I creates or overwrites C:\driversetchosts, which has the following entries:
127.0.0.1 localhost
205.177.124.66 auto.search.msn.com
Troj/StartPa-I creates an HTML stylesheet in C:hh.htt and creates associated registry entries in
HKLMSoftwareMicrosoftInternet ExplorerStylesUser Stylesheet and
HKLMSoftwareMicrosoftInternet ExplorerStylesUse My Stylesheet.
The URL files will have links to porn-related websites.
Troj/Startpa-Z is a simple Trojan that makes changes to Internet Explorer settings via the registry.
Troj/Startpa-Z changes the default start page of Internet Explorer to the URL http://aifind.info/ and will add a list of URLs containg adult content to the favourites folder. The Trojan will also change the following registry entries:
HKCUSoftwareMicrosoftInternet ExplorerStyles
Use My Stylesheet = 1
HKCUSoftwareMicrosoftInternet ExplorerStyles
User Stylesheet = hh.htt
HKLMSoftwareMicrosoftInternet ExplorerStyles
Use My Stylesheet = 1
HKLMSoftwareMicrosoftInternet ExplorerStyles
User Stylesheet = hh.htt
The stylesheet file hh.htt is detected by Sophos Anti-Virus as Troj/Startpa-BG.
Troj/Startpa can be removed from Windows computers automatically with the following Resolve tools:
Windows disinfector
STRTPGUI is a disinfector for standalone Windows computers. To use it you have to do the following:
- Open STRTPGUI.com file from your desktop after downloading it.
- Click on the Start Scan Button.
- Wait for the process to complete.
Command line disinfector
STRTPSFX.EXE is a self-extracting archive containing STRTPCLI, a Resolve command line disinfector for use by system administrators on Windows networks.
Resolve for Banker-R 1.06
A tool that removes Banker-R trojan more>> A tool that removes Banker-R trojan
Resolve is the name for a set of small, downloadable Sophos utilities designed to remove and undo the changes made by certain viruses, Trojans and worms.
They terminate any virus processes and reset any registry keys that the virus changed. Existing infections can be cleaned up quickly and easily, both on individual workstations and over networks with large numbers of computers.
Troj/Banker-R can be removed from Windows computers automatically with the following Resolve tools:
Windows disinfector
BDLAAGUI is a disinfector for standalone Windows computers. To use it you have to do the following:
- Open BANKRGUI.com file from your desktop after downloading it.
- Click on the Start Scan Button.
- Wait for the process to complete.
Command line disinfector
BANKRSFX.EXE is a self-extracting archive containing BANKRCLI, a Resolve command line disinfector for use by system administrators on Windows networks.
Resolve for Daoser-C 1.07
A tool that removes Daoser-C trojan more>> A tool that removes Daoser-C trojan
Resolve is the name for a set of small, downloadable Sophos utilities designed to remove and undo the changes made by certain viruses, Trojans and worms. They terminate any virus processes and reset any registry keys that the virus changed. Existing infections can be cleaned up quickly and easily, both on individual workstations and over networks with large numbers of computers.
Troj/Daoser-C is a Trojan for the Windows platform.
Troj/Daoser-C will modify the start page for Internet Explorer.
Troj/Daoser-C may display popups and spy on web searches and browsing habits. Troj/Daoser-C is a Trojan for the Windows platform.
Troj/Daoser-C will modify the start page for Internet Explorer.
Troj/Daoser-C may display popups and spy on web searches and browsing habits.
When the Trojan is installed the following files are created:
ServicesSVCHOST32.DLL
Servicessecurity.exe
Servicessvchost.dll
Servicessvchost.exe
where is a string of letters and numbers.
The following registry entry is created to run svchost.exe on startup:
HKLMSOFTWAREMicrosoftWindowsCurrentVersionRun
Service Host
ServicesSVCHOST.EXE
The Trojan changes the Start Page for Microsoft Internet Explorer by altering the registry entry:
HKCUSoftwareMicrosoftInternet ExplorerMainStart Page
Troj/Daoser-C can be removed from Windows computers automatically with the following Resolve tools:
Windows disinfector
DAOSRGUI is a disinfector for standalone Windows computers. To use it you have to do the following:
- Open DAOSRGUI.com file from your desktop after downloading it.
- Click on the Start Scan Button.
- Wait for the process to complete.
Command line disinfector
DAOSRSFX.EXE is a self-extracting archive containing DAOSRCLI, a Resolve command line disinfector for use by system administrators on Windows networks.
Resolve for Surila-E 1.07
A tool that remove Surila-E trojan more>> A tool that remove Surila-E trojan
Resolve is the name for a set of small, downloadable Sophos utilities designed to remove and undo the changes made by certain viruses, Trojans and worms. They terminate any virus processes and reset any registry keys that the virus changed.
Existing infections can be cleaned up quickly and easily, both on individual workstations and over networks with large numbers of computers.
Troj/Surila-E is a backdoor Trojan which allows a remote intruder to gain access and control over the computer.
Troj/Surila-E includes functionality to access the internet and communicate with a remote server via HTTP.
When first run Troj/Surila-E copies itself to:
csrss.exe
msupdate.exe
and creates a file dodrrr.exe detected as Troj/Surila-D.
Troj/Surila-E modifies the system file sfc_os.dll in an attempt to disable the Windows System File Checker. The Trojan may do this in order to modify further system files.
The following registry entries are created to run msupdate.exe on startup:
HKCUSoftwareMicrosoftWindowsCurrentVersionRun
msupdate
msupdate.exe
HKLMSOFTWAREMicrosoftWindowsCurrentVersionRun
msupdate
msupdate.exe
HKLMSOFTWAREMicrosoftWindowsCurrentVersionRunOnce
msupdate
msupdate.exe
Registry entries are set as follows:
HKCUSoftwareMicrosoftInternet Explorer
mtxqwnm
nVKHFQU
HKCUSoftwareMicrosoftInternet Explorer
veer
40040
HKCUSoftwareMicrosoftWindowsCurrentVersionPolicies
DisableRegistryTools
0
HKLMSOFTWAREMicrosoftWindowsCurrentVersionpolicies
DisableRegistryTools
0
HKLMSOFTWAREMicrosoftOle
WINRUN
msupdate.exe
HKLMSOFTWAREMicrosoftWindows NTCurrentVersionWinlogon
SFCScan
0
HKLMSYSTEMCurrentControlSetControlLsa
WINRUN
msupdate.exe
HKLMSOFTWAREMicrosoftWindows NTCurrentVersionWinlogon
SFCDisable
ffffff9d
Troj/Surila-E can be removed from Windows computers automatically with the following Resolve tools:
Windows disinfector
SURILGUI is a disinfector for standalone Windows computers. To use it you have to do the following:
- Open SURILGUI.com file from your desktop after downloading it.
- Click on the Start Scan Button.
- Wait for the process to complete.
Command line disinfector
SURILSFX.EXE is a self-extracting archive containing SURILCLI, a Resolve command line disinfector for use by system administrators on Windows networks.
Credit Card Relief 5.0
Credit Card Relief search toolbar for Internet Explorer. Consumer Debt Law is committed to becoming the primary destination for consumers who are determined to resolve their debts. more>> Credit Card Relief search toolbar for Internet Explorer. Debts accumulates over many years, and without proper legal assistance, it can take a lifetime to finally get out of debt. Consumer Debt Law is committed to becoming the primary destination for consumers who are determined to resolve their debts and improve their financial well-being.
System Requirements: Internet Explorer
<<lessResolve for Dloadr-AKL 1.07
A tool that removes Dloadr-AKL trojan more>> A tool that removes Dloadr-AKL trojan
Resolve is the name for a set of small, downloadable Sophos utilities designed to remove and undo the changes made by certain viruses, Trojans and worms. They terminate any virus processes and reset any registry keys that the virus changed. Existing infections can be cleaned up quickly and easily, both on individual workstations and over networks with large numbers of computers.
Troj/Dloadr-AKL is a downloader Trojan for the Windows platform.
Troj/Dloadr-AKL may attempt to download a file to "C:28348177711.exe" and execute it. The downloaded file is detected as Troj/FireSpy-A.
Troj/Dloadr-AKL also attempts to inject itself into "explorer.exe" to avoid detection.
Troj/Dloadr-AKL can be removed from Windows computers automatically with the following Resolve tools:
Windows disinfector
DLAKLGUI is a disinfector for standalone Windows computers. To use it you have to do the following:
- Open DLAKLGUI.com file from your desktop after downloading it.
- Click on the Start Scan Button.
- Wait for the process to complete.
Command line disinfector
DLAKLSFX.EXE is a self-extracting archive containing DLAKLCLI, a Resolve command line disinfector for use by system administrators on Windows networks.
Resolve for BagleDl-AB 1.07
A tool that removes BagleDl-AB trojan more>> A tool that removes BagleDl-AB trojan
Resolve is the name for a set of small, downloadable Sophos utilities designed to remove and undo the changes made by certain viruses, Trojans and worms.
They terminate any virus processes and reset any registry keys that the virus changed. Existing infections can be cleaned up quickly and easily, both on individual workstations and over networks with large numbers of computers.
Troj/BagleDl-AB is a Trojan for the Windows platform.
When first run Troj/BagleDl-AB copies itself to hloader_exe.exe and creates the file hleader_dll.dll. Both these files are detected as Troj/BagleDl-AB. Troj/BagleDl-AB is a Trojan for the Windows platform.
When first run Troj/BagleDl-AB copies itself to hloader_exe.exe and creates the file hleader_dll.dll. Both these files are detected as Troj/BagleDl-AB.
Troj/BagleDl-AB attempts to inject the dropped file hleader_dll.dll into the process explorer.exe.
The following registry entries are created to run hloader_exe.exe on startup:
HKCUSoftwareMicrosoftWindowsCurrentVersionRun
auto__hloader__key
hloader_exe.exe
HKLMSOFTWAREMicrosoftWindowsCurrentVersionRun
auto__hloader__key
hloader_exe.exe
Troj/BagleDl-AB attempts to download and execute files from a number of remote websites.
Troj/BagleDl-AB can be removed from Windows computers automatically with the following Resolve tools:
Windows disinfector
BAGDLGUI is a disinfector for standalone Windows computers. To use it you have to do the following:
- Open BAGDLGUI.com file from your desktop after downloading it.
- Click on the Start Scan Button.
- Wait for the process to complete.
Command line disinfector
BAGDLSFX.EXE is a self-extracting archive containing BDLAACLI, a Resolve command line disinfector for use by system administrators on Windows networks.
Resolve for DownLd-AAP 1.07
A tool that removes DownLd-AAP trojan more>> A tool that removes DownLd-AAP trojan
Resolve is the name for a set of small, downloadable Sophos utilities designed to remove and undo the changes made by certain viruses, Trojans and worms. They terminate any virus processes and reset any registry keys that the virus changed. Existing infections can be cleaned up quickly and easily, both on individual workstations and over networks with large numbers of computers.
Troj/DownLd-AAP is a downloading Trojan for the Windows platform.
Troj/DownLd-AAP downloads a file from a preconfigured website and executes it.
Troj/DownLd-AAP also includes functionality to spread via removable drives by copying itself with the filename Setup.pif. The file autorun.inf may be created to run Troj/DownLd-AAP once the removable drive is connected.
When first run Troj/DownLd-AAP copies itself to moviemk.exe and creates the file .txt.
The file moviemk.exe is registered as a new system driver service named "Medie Sariel Number Services", with a display name of "Medie Sariel Number Services" and a startup type of automatic, so that it is started automatically during system startup. Registry entries are created under:
HKLMSYSTEMCurrentControlSetServicesMedie Sariel Number Services
Troj/DownLd-AAP can be removed from Windows computers automatically with the following Resolve tools:
Windows disinfector
DLAPPGUI is a disinfector for standalone Windows computers. To use it you have to do the following:
- Open DLAPPGUI.com file from your desktop after downloading it.
- Click on the Start Scan Button.
- Wait for the process to complete.
Command line disinfector
DLAPPSFX.EXE is a self-extracting archive containing DLAPPCLI, a Resolve command line disinfector for use by system administrators on Windows networks.
Resolve for BagleDl-AA 1.07
A tool that removes BagleDl-AA trojan more>> A tool that removes BagleDl-AA trojan
Resolve is the name for a set of small, downloadable Sophos utilities designed to remove and undo the changes made by certain viruses, Trojans and worms.
They terminate any virus processes and reset any registry keys that the virus changed. Existing infections can be cleaned up quickly and easily, both on individual workstations and over networks with large numbers of computers.
Troj/BagleDl-AA is a Trojan for the Windows platform.
Troj/BagleDl-AA attempts to terminate processes and services, delete files and registry entries, and block access to URLs related to anti-virus and security programs. Troj/BagleDl-AA is a Trojan for the Windows platform.
When first run Troj/BagleDl-AA copies itself to antiav_exe.exe and creates the file antiav_dll.dll. Both these files are detected as Troj/BagleDl-AA.
Troj/BagleDl-AA attempts to inject the dropped file antiav_dll.dll into the process explorer.exe.
The following registry entries are created to run antiav_exe.exe on startup:
HKCUSoftwareMicrosoftWindowsCurrentVersionRun
auto__antiav__key
antiav_exe.exe
HKLMSOFTWAREMicrosoftWindowsCurrentVersionRun
auto__antiav__key
antiav_exe.exe
Troj/BagleDl-AA attempts to terminate several processes and services related to anti-virus and security programs, to delete related files, to modify C:boot.ini to delete related files on system startup, to block access to related websites, to delete related registry entries, and to delete registry entries at the following location to stop related files from running on system startup:
HKLMSOFTWAREMicrosoftWindowsCurrentVersion
Run
HKCUSoftwareMicrosoftWindowsCurrentVersion
Run
Troj/BagleDl-AA can be removed from Windows computers automatically with the following Resolve tools:
Windows disinfector
ENFALGUI is a disinfector for standalone Windows computers. To use it you have to do the following:
- Open ENFALGUI.com file from your desktop after downloading it.
- Click on the Start Scan Button.
- Wait for the process to complete.
Command line disinfector
BDLAASFX.EXE is a self-extracting archive containing BDLAACLI, a Resolve command line disinfector for use by system administrators on Windows networks.