Remove a Randomly Named Trojan Virus
Warning: Be sure to make a backup copy of your registry prior to making any changes to it.
Go to Start>> Search all files and folders. Search for the viruses file name and delete it where-ever it is found.
Navigate to the following Registry keys one at a time:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg
Click the last string entry (eg: startupreg & run) to empty its contents into the right pane. Look for entries that reference your specific Trojan file. Delete the strings that contain such reference. Be sure that you do not delete any string values in the left pane.
Update your Antivirus software and run a full system scan. If your antivirus software states that your system is clean, you will now need to remove all of your restore points as the virus may reside there. The next time that you would use system restore, you will re-infect your system.
Go to Start>> Control Panel>> System>> System Restore tab. Check the box to "Turn off system restore on all drives".
Follow the instructions in #1 above to restore your system restore on all drives by unchecking the entry.
Click "Create a Restore Point" then click Next.
Note: If everything seems to be running well at this point, delete the backup copy of your registry. Then, empty your recycle bin.
0 Comments:
Post a Comment