spyware removal instructions

Ashley removal

Spyware Ashley Information
Name: Ashley
Category: RAT
Author: Nexzus
Coded in: Visual Basic 6. requires msvbvm60.dll Servers compressed with UPX
Dangerous: Yes
Ashley belongs to RAT spyware category.
It's presense means that your computer is infected with malicious software and is insecure.
Ashley description by Nexzus:
Vendor: ´This is a uploader trojan that is meant to upload a bigger trojan. It also server as an IRC worm. Wanna have unlimited Victims? Sent this to your victim & the bigger trojan will be uploded onto his comp. Also the next time he goes to irc, Ashley will auto attempt to spread herself to other users on the irc. When someone else on irc accepts it & execute it, It will also download that bigger trojan from the URL you specified & it will also attempt to spread itself on irc. Therefore you´ll get more & more victims. Sure some may say few ppl on irc accepts anonamous any file anymore. But there are always guilleble users out there. It may spread slower but it will still spread. Even if it doesn´t, just treat this as a uploader trojan. Version 1.0.0c & version 1.0.0.d of ashley also attempts to spread itself via outlook e-mail. Therefor if you use version c or d of it, you´ll get much more victims. HOWEVER both Versions has never been tested before & might not work. But do test it cos at the most only the e-mail part won´t work, the irc & uploader part should work. If you do test it, please send some feed backs to me. The four versions of Ashley: -Version 1.0.1a is an uploader trojan & irc worm.[14kb] -Version 1.0.1b is just an uploader trojan & will NOT attempt to spread itself through irc. [12.5kb yaya I know it is a bit big] -Version 1.0.1c is an uploader cum irc worm & Outlook worm. [15.5kb Never tested before] -Version 1.0.1d similar to version c except for different method/ algorithm of spreadin via outlook.[15kb ] -Version 1.0.0c outlook spreading was created based on Senna Spy Worm Algorithm & MIGHT be detected by Av. Nexzus This is a uploader trojan that is meant to upload a bigger trojan. It also server as an IRC worm. Wanna have unlimited Victims? Sent this to your victim & the bigger trojan will be uploded onto his comp. Also the next time he goes to irc, Ashley will auto attempt to spread herself to other users on the irc. When someone else on irc accepts it and execute it, It will also download that bigger trojan from the URL you specified & it will also attempt to spread itself on irc. Therefore you´ll get more & more victims. Sure some may say few ppl on irc accepts anonamous any file anymore. But there are always guilleble users out there. It may spread slower but it will still spread. Even if it doesn´t, just treat this as a uploader trojan. Version 1.0.0c & version 1.0.0.d of ashley also attempts to spread itself via outlook e-mail. Therefor if you use version c or d of it, you´ll get much more victims. HOWEVER both Versions has never been tested before & might not work. But do test it cos at the most only the e-mail part won´t work, the irc & uploader part should work. If you do test it, please send some feed backs to me. Any comments or bugs(I am sure theres plenty of them) or suggestion, sent mail to nexzus@Innervoid.org ############# #What´s new # ############# -Optional Error msg & Configurable msg. -Destroy Victim´s Netstat upoon d/l of the trojan from the web. [For paronoid ppl] -Mass Server Command 1st you enter the url of the txt file u want the server to check for command. Eg: geocities.com/nexzus/test.txt. Now u up load the a.txt file into that geocities add. Everytime ashley starts up it will get the command from the test.txt file on geocities. As for wat are the commands . In test.txt it contains only one digit to represent that commands: "1" To Stop all Trojan Activites "2" To redownload the trojan from the web-site. "3" Icq notify you everytime the victim is online. This is useful incase your other trojan icq notification does not work. Some sort of a backup icq notification. "9" to destroy the victim comp [ please dun abuse] So for eg u want the victim to icq notify u everytime he has online. go in a.txt file just type: 3 in a.txt.That is it.. Now save a.txt & upload it to geocities etc..] -Banner Clicking This option is for banner displaying. You enter the full path of the banner cgi´s url & whenever the person is online, he will retrive the banner 50 times. Steal note.. it only RETRIVIE the banner , not CLICKING them.. So for those ads that requires clicking this won´t work.. BUT there are ads that pay u just for each time a banner is display. eg allclicks.com etc..... basically this is also for webmasters who are using banner exchange stuff. -Added a updater.exe. Antivirus is detecting this rather quick. So i´ll release a undetected servers every 2 weeks or so. It can only be d/l through the updater.Check for updates every 2 weeks. When running the updater, it´ll open your web explorer & bring u to our sponsers page. This allow us to make some $ & to server u better. So plz do support us. ############ # Servers # ############ There are 3 different Servers this time: -ashley1.1.0a Is just the basic one without any worm capability -ashley1.1.0b uploads the trojan from the web & also spread itself through mirc & outlook. -ashley1.1.0c is the same as version b but base on different algorithm. *note ashley1.1.0b outlook spreading was base on senna spy worm algorithm As usualy version a is working perfectly & version b & c has not been tested fully. Try them & let me know. That is all. Any mails sent them to nexzus@innervoid.org ############ #Shoutouts:# ############ Wildphir3 MaskDemon -This guy help me design some fo the graphics.. visit him at www.morbus.co.uk All the beta testers Eveyone at Innervoid & of cos Ashley *grinz
This RAT is also known as:
Backdoor.Ashley.100.
Backdoor.Ashley.100.b.
Backdoor.Ashley.100.d.
Backdoor.Ashley.101.a.
Backdoor.Ashley.101.c.
Backdoor.Ashley.110.
Backdoor.Ashley.110.a.
Backdoor.Ashley.110.b.
Backdoor.Ashley.110.c.

>> Delete Ashley automatically - Download Spyware Doctor

Ashley Removal Instructions
Kill the following processes
ashley.exe, editor.exe, updater.exe
Remove the following files
ashley.exe, editor.exe, readme.txt, updater.exe.

Bookmark Ashley page

 Previous Spyware: Remove Ashiyane Next Spyware: Remove Ashley 1.01