Discovered: November 9, 2001
Updated: February 13, 2007 11:37:44 AM
Also Known As: Backdoor-SG
Type: Trojan Horse
Delete files that are detected as Backdoor.Nerte, and reverse the changes that the Trojan made to the registry.
To remove the Trojan:
- Run LiveUpdate to make sure that you have the most recent virus definitions.
- Start Norton AntiVirus (NAV), and make sure that NAV is configured to scan all files. For instructions on how to do this, read the document How to configure Norton AntiVirus to scan all files.
- Run a full system scan.
- Delete all files that are detected as Backdoor.Nerte. Deleted files must be either replaced from a clean backup or reinstalled.
To edit the registry:
CAUTION: We strongly recommend that you back up the system registry before you make any changes. Incorrect changes to the registry could result in permanent data loss or corrupted files. Please make sure that you modify only the keys that are specified. Please see the document
How to back up the Windows registry before you proceed.
- Click Start, and click Run. The Run dialog box appears.
- Type regedit and then click OK. The Registry Editor opens.
- Navigate to and delete the following keys:
HKEY_LOCAL_MACHINE\Software\Nerte
HKEY_LOCAL_MACHINE\Software\Nerte\TR
- Navigate to the key
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
- Follow the instructions for your operating system:
- Windows 95/NT
- In the right pane, delete the value
ScanRegistry <Path>\nsrvnt.exe
- Exit the Registry Editor.
- Windows 98/Me
- In the right pane, double-click the value
ScanRegistry <Path>\nsrvnt.exe
- In the Value Data box, change the text to
C:\Windows\scanregw.exe /autorun
NOTE: If you installed Windows to a location other then C:\Windows, make the appropriate path substitution when you enter the text.
- Click OK, and then exit the Registry Editor.
Writeup By: Douglas Knowles