Download.Ject Payload Detection and Removal Tool
NoticeThis tool is no longer available. It has been replaced by the Microsoft Windows Malicious Software Removal Tool. For more information about the Malicious Software Removal Tool, click the following article number to view the article in the Microsoft Knowledge Base:890830 (http://support.microsoft.com/kb/890830/)
The Microsoft Windows Malicious Software Removal Tool helps remove specific, prevalent malicious software from computers that are running Windows Server 2003, Windows XP, or Windows 2000
On This PageSUMMARYMicrosoft has learned of a Trojan horse program that is named W32/Berbew (variants A-H) that is downloaded after a Microsoft Windows-based client computer is infected with the Download.Ject malware. This problem occurs when a user visits a Web site that is hosted on a server that is running Microsoft Internet Information Services (IIS) and that has been infected by JS.Scob. The Web pages that are downloaded to the user’s computer contain an additional JavaScript program that downloads the Backdoor:W32/Berbew Trojan horse. Backdoor:W32/Berbew is also known as Backdoor-AXJ, Webber, or Padodor. When this Trojan horse runs on the user’s computer, it performs several actions, including the following:
Microsoft has released a tool to help you remove Backdoor:W32/Berbew Trojan horse variants from your computer. You can download this tool from the Microsoft Download Center and run it on your computer to remove Backdoor:W32/Berbew.A, Backdoor:W32/Berbew.B, Backdoor:W32/Berbew.C, and Backdoor:W32/Berbew.D, Backdoor:W32/Berbew.E, Backdoor:W32/Berbew.F, Backdoor:W32/Berbew.G and Backdoor:W32/Berbew.H infections. Technical updates
SYMPTOMSYou may experience one or more of the following symptoms:
CAUSEThis behavior occurs because your computer is infected with
the Backdoor:W32/Berbew Trojan horse. Backdoor:W32/Berbew is delivered by the
Download.Ject Trojan horse. For more information about how to determine if your
computer is infected with a variant of Backdoor:W32/Berbew, visit the following
Microsoft Web site: http://onecare.live.com/standard/en-us/virusenc/ (http://onecare.live.com/standard/en-us/virusenc/) RESOLUTIONAntivirus software with up-to-date signatures will help
prevent the Backdoor:W32/Berbew Trojan horse from infecting your
computer. Important We also recommend that you use an Internet firewall and an antivirus program with up-to-date signatures, and that you keep both Windows and your programs up-to-date. For more information about how to prevent viruses, and about how to recover from virus infections, click the following article number to view the article in the Microsoft Knowledge Base: 129972 (http://support.microsoft.com/kb/129972/)
Computer viruses: description, prevention, and recovery
Download and setup informationPrerequisitesThe Download.Ject Payload Detection and Removal Tool has the following prerequisites:
827218 (http://support.microsoft.com/kb/827218/)
How to determine whether your computer is running a 32-bit version or a 64-bit version of the Windows operating system
If these prerequisites are not met, the
installation will not work, and you will receive an error message. For more
information about the error message, view the following log file: %Windir%\Debug\Berbcln.log Additionally, we recommend that you install the Windows update to
disable the ADODB.stream object in Internet Explorer before you run the removal
tool. Although the removal tool will remove the Trojan horse from infected
computers, it will not prevent re-infection if your computer is still
vulnerable. By installing the critical update, you can help prevent additional
downloads of malware from a Download.Ject-infected
server.For more information about the Windows update to disable the ADODB.stream object, click the following article number to view the article in the Microsoft Knowledge Base: 870669 (http://support.microsoft.com/kb/870669/)
How to disable the ADODB.Stream
object from Internet Explorer
Restart requirementYou do not have to restart your computer after you install this tool.Usage informationImportant Before you follow these steps, make sure that you have backed up all your important data.When you install the Download.Ject Payload Detection and Removal Tool and accept the end-user license agreement (EULA), the installation package extracts the Berbcln.exe file to a temporary folder, and then the removal tool runs. The removal tool verifies that your computer meets the prerequisites that are listed in the "Prerequisites" section. If the prerequisites are met, the removal tool takes the following actions:
Command-line switchesThe removal tool installer supports the following command-line switches:
197147 (http://support.microsoft.com/kb/197147/)
Command-line switches for IExpress
software update packages
The removal tool supports the following command-line
switch:
Removal informationThe Berbcln.exe file is automatically deleted from its temporary location after the removal tool runs. You can delete the tool's installer package after you install the removal tool.Note After you install the Download.Ject Payload Detection and Removal Tool, it does not appear in the Installed programs list in the Add/Remove Programs tool in Control Panel. MORE INFORMATIONIn more recent versions of Robocopy, such as version XP010, the /SECFIX switch has been deprecated. To refresh security information for existing destination files and folders without copying file data, use the /IS switch together with the /COPY switch without the D flag. For example, /IS /COPY:SOU refreshes all security information for all selected files without copying any file data. For more information, see the "Selectively Copying File Data" topic in the Robocopy.doc file. APPLIES TO
| Article Translations
|
Back to the top
