SpywareGuide powered by Actiance Security Labs
Search SpywareGuide Database & Site
Home Access the Guide
List of Products List of Companies List of Categories
Tools
X-RayPC
Terms and Definitions
 
Full Name:
Trojan.Joex Websearch   Read More
Type: Trojan
Also Known as: Troj/Digidor-A (SOPHOS) Trojan.Startpage.Q
SG Index: 5 [Explain]
Removal tools: List of products that detect/remove/protect against Trojan.Joex:
  • IM, P2P control, malware prevention and web filtering in single appliance: Unified Security Gateway
  • Category Description: Trojans are malicious applications that pose themselves as legitimate software in order to trick users to install them. Once on the victim's machine, it may run any number of malicious process to steal vital information or inflict damage to other software.
    Official Description: Disables the Windows Task Manager and changes Internet Explorer's home page. Is capable of downloading and executing files.
    Also this trojan hides its files by changing registry entries. Does not allows the users to view the hidden files.
    Information URL: http://joyiex.com/
       
    Manual removal: 1. Click Start > Run.
    2. Type regedit
    3. Click OK.
    4. Navigate to the subkey:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    In the right pane, delete
    "ctfnom.exe" = "%Windir%\SVOHOST.exe"

    5. Navigate to the subkey:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
    In the right pane,change the Data for "Shell" to Explorer.exe

    6. Navigate to the subkey:
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\
    Policies\system
    In the right pane, delete the value:
    "DisableTaskMgr" = "1"

    7. Navigate to the subkey:
    HKEY_CURRENT_USER\Software\Policies\Internet Explorer\ControlPanel
    In the right pane, delete the value:
    "HomePage" = "1"

    8. Navigate to the subkey:
    HKEY_CLASSES_ROOT\txtfile\shell\open
    In the right pane, modify the value:
    "command" = "%System%\lsasa.exe "%1""
    to:
    "command" = "%System%\notepad.exe "%1""

    9. Close the Registry Editor.
    Properties:
  •  Adds other software
  •  Changes browser
  • Click here to leave feedback for this product

    Recent Modifications
    2012-5-10  NetSpy
    2012-5-1  Unclassified Adware/Spyware
    2012-4-11  Adult Networks/Services
    2012-4-11  CoolWebSearch
    2012-3-13  Misc. Exploits
    2012-2-24  Zango Times
    2012-2-24  About Blank
    2012-1-30  HostSeeker Toolbar
    2012-1-13  2000Cracks
    2012-1-13  7AdPower Dialer
     
    Company  | Site and Spyware FAQ
    © Copyright 2003-2011, Actiance, Inc. All rights reserved.   Privacy Policy