Troj/DLoader-A has several components. It downloads several files from
www.wwws1.com and installs them on the local machine.
These files include: C:\Windows\absr.exe, C:\Windows\ausvc.exe, C:\Windows\auupg.exe, C:\Windows\bvt.exe, C:\Windows\ea.bin and C:\Windows\mbtcd.bak.
During the installation numbers of registry entries are created including:
HKLM\Software\Microsoft\Windows\CurrentVersion
\Run\ABsr = C:\Windows\absr.exe
HKLM\Software\Microsoft\Windows\CurrentVersion
\Run\ausvc = C:\Windows\ausvc.exe
HKLM\Software\Microsoft\Windows\CurrentVersion
\Run\SysScan = C:\Windows\bvt.exe
Recovery
Please read the instructions for removing Trojans.
Windows NT/2000
In Windows NT/2000 you will also need to delete the following registry keys. The removal of these keys is optional in Windows 95/98/Me.
At the Windows taskbar, select Start|Run. Type 'Regedit' and press return. The registry editor will open.
Before you edit the registry, you should make a backup. In the Registry menu, click on Export Registry File, in Export Range select All, then save your registry as Backup.
Locate the HKEY_LOCAL_MACHINE key:
HKLM\Software\Microsoft\Windows\CurrentVersion
\Run\
and delete these three references:
ABsr = C:\Windows\absr.exe
ausvc = C:\Windows\ausvc.exe
SysScan = C:\Windows\bvt.exe
Close the Registry Editor and restart your computer.