Trojan:Win32/Necurs is from the Necurs family of threats. It has many different varients including Trojan:Win32/Necurs.A, Win32/TojanDownloader.Necurs.B (ESET),Trojan-Dropper.Win32.Necurs.va (Kaspersky) . Many anti-virus client will pick this trojan virus up as Necurs.
What Necurs Does:
Like any good trojan virus out there, Necurs will go out and download malware and other programs. Expect this software to open a back door into your computer so a remote user can take it over.
This is the REALY BAD kind of virus. It will also disable most antivirus clients from running on your computer. This is down through the Necurs.A varient.
Once infected users may have limited access to a number of programs on their computer. They will most likely also have a fake anti-virus client or other such fake programs get installed onto their computer.
the threat level for this virus is HIGH. It needs to be removed ASAP.
How to Remove Necrus?
For those that have trouble following this guide or just want an expert to remove this virus for you we recommend http://www.pcninja.com. This remote computer repair company can fully remove Necrus on your computer and get you back up and going in no time. Feel free to ask any questions you have about the guide below and we will do our best to answer them in a timely fashion.
Step 1. We need to locate the Necurs files. The simplest way to do this is to run SpyHunter. You may need to be in safe mode with networking in order to download and install the client. Learn more on how to do this here.
Using SpyHunterwill help you locate the exact file paths of this threat and then you can manuely remove them or just purchase the client and have it remove all virus traces found.
Where the Necrus Traces Are Located:
- %windir%\Installer\<random GUID>\syshost.exe
- %TEMP%\<random GUID>.tmps
You can browse to the above folders on your computer and delete the above files. We found these traces using Spyware Doctor with Antivirus. Just note that it can be hard to locate them as every computer has a different GUID name. You can however sort the files by date and see which ones where just created. This can help narrow down your options.
Once these traces are deleted you should be able to use your computer again. We will now run a scan using the free Microsoft Safety Scanner: http://www.microsoft.com/security/scanner/en-us/default.aspx. You can run this scan before the Spyware Doctor with Antivirus program. However be sure to scan with both to ensure you have found all virus traces on your computer.
The Necrus trojan virus can be hard to remove because it does a good job hiding on your computer. Many good antivirus clients should be able to pick this client up and delete it. We have successfully deleted this client and all virus threats using Spyware Doctor with Antivirus so that is what we are recommending here.
Outside Resources:
http://www.nictasoft.com/viruslib/malware/Trojan-Dropper.Win32.Necrus.a
Speak Your Mind