I am not sure if this will remove this trojan but it is a great antimalware program that can also repair hosts files etc when it removes malware.
Comodo Firewall may also help as it should warn you about any connection attempts if your system is infected.
For removing this nasty with NOD32 (assuming NOD32 detects it) then you should first disable system restore on your computer and then run a full scan with NOD32.
i install boclean …and it never see the trojan …before i install nod32 i used antivirus here …
but trojan still appear …
important note :
i used and dsl internet ( lan network ) …i try to open my friend computer and i see also the trojan try to open itself …and i try another computer in lan …and i see this trojan …
I am sure someone there will be able to help you with either removal or submitting the trojan.
I am surprised BOClean does not detect this malware. If you manage to obtain a copy of the trojan perhaps you would consider submitting it to Comodo to help improve detection in BOClean and CAVS:
You can email them to: malwaresubmit [ at ] avlab.comodo.com .
You may want to specify in the subject line “Malware?” for clarity’s sake.
Zip and password protect the file with “infected” including that information in the email body.
And the websites you referenced are not the same:
832821.com/rr.html
832821.cn/sysdown.exe
And, what are the rules for posting direct links to malware?
Could a mod please look at this post to protect the innocent …
Edit:
Forum Policy:
* Live Malware. Comodo is in the business of helping secure the internet, not propagating malware. Thus, it is not the appropriate place to attach or link live malware (viruses, trojans, rootkits, etc) to posts. In general, a link to the download site for 'malware' tests/demos and other 'proof of concept' applications are acceptable, provided they are not intended or designed to cause harm to a computer.
EDIT: Removed WWW to disable remaining link. N.T.T.W