Many newcomers know more about security issues, and the computer in Trojan horses don't know how to clear. Although there are many software that clear the Trojan horse, you can automatically remove Trojans. But you don't know how the Trojan is running in the computer. If you read this article, you will understand some of the principles of Trojan. 1. Ice v1.1 v2.2 Ice is the best Trojan Clear Trojan v1.1 Open Registry Regedit Click on the directory to: hkey_local_machine / software / millosoft / windows / currentversion / Run Find the following two paths, and delete " C: / windows / system / kernel32.exe "C: / Windows / System / Sysexplr.exe" Close Regedit Restart to MSDOS Mode Delete C: / Windows / System / Kernel32.exe and C: / Windows / System / SYSEXPLR The .exe Trojan is restarted. OK Clear Trojan V2.2 server program, the path user can be freely defined, and the key name written to the registry can also be defined. Therefore, it cannot be clearly stated. You can check the registry and delete the suspicious file path. Restart to the MSDOS method Remove the Trojan to restart Windows corresponding to the registry. OK 2. ACID Battery v1.0 Clear Trojan: Open Registry Regedit Click on: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / Run Delete Explorer = "C: /Windows/expiorer.exe" close REGET RA Start to MSDOS mode Delete C: /Windows/expiorer.exe Trojan Note: Do not delete the correct Explorer.exe program, there is only the difference between I and L between them. Restart. OK 3. ACID Shiver V1.0 1.0MOD LMACID Clear Trojans: Restart to MSDOS mode Delete C: /Windows/msgsvr16.exe and return to the Windows system Open Registry Regedit Click on: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / Run the right to delete Explorer = "C: /WINDOWS/MSGSVR16.EXE" HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RunServices the right to delete Explorer = "C: /WINDOWS/MSGSVR16.EXE" Close Regedit again start up. OK Restart to MSDOS mode Delete C: /Windows/WintOr.exe and return to the Windows system Open Registry Regedit Click on: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / Run Delete Wintour = "C: / Windows / WintOour.exe "HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / Runservices Delete Wintour =" C: /Windows/Wintour.exe "off the right. Close the regedit restart.
OK 4. AMBUSH Clear Trojan Steps: Open Registry Regedit Click on: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN / Delete ZKA = "ZCN32.exe" Close Regedit Restart to MSDOS Mode Delete C: / Windows / zcn32.exe restarts. OK 5. AOL Trojan Clear Trojan Steps: Start to MSDOS mode Delete C: / command.exe (unable to cancel the file before delete) Note: Do not delete the true command.com file. Delete C: / Americ ~ 1.0 / BudDyl ~ 1.Exe (Implied Properties canceled before delete) Delete C: / Windows / System / Norton ~ 1 / Regist ~ 1.exe Open the Win.ini file in [Windows] "Run =" and "LOAD =" to the Path of Trojm Horse, must be cleared: run = loading = Save Win.ini to correct the registry regedit Click on the directory: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / Run Delete WinProfile = C: /command.exe on the right, restarts Windows. OK 6. Asylum V0.1, 0.1.1, 0.1.2, 0.1.3 Mini 1.0, 1.1 Clear Trojans: Note: Trojan Default file name is WinCMP32.exe, however programs can change the file name at will. We can remove Trojans according to the System.ini and Win.ini modified by Trojans. Open the System.ini file in [Boot] has a "shell = file name". The correct file name is Explorer.exe if it is not "Explorer.exe", then that file is a Trojan, find it out, delete. Save Exit System.ini Open the win.ini file in [Windows] There is a run = if you see = the path file name, you must delete it. The correct thing should be Run = no. = The back path file name is Trojan and looks out, delete it. Save exit Win.ini. OK 7. AttackFTP Clear Trojans: Open the win.ini file under [Windows] There is load = wscan.exe to remove wscan.exe, correctly, LOAD = save exit Win.ini.
Open Registry Regedit Click on: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CURRENTVERSION / RUN Remove Rewer = "WSCAN.EXE / S" Close Regedit, restart to the MSDOS system to remove C: / Windows / System / WSCAN. EXE OK 8. Back Construction 1.0 - 2.5 Clearing Trojans: Open Registry Regedit Click on: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / Run Delete "C: /Windows/cmctl32.exe" close Regedit, Re-Re- Start to the MSDOS system to remove C: /Windows/cmctl32.exe OK 9. Backdoor V2.00 - V2.03 Clear Trojan step: Open Registry Regedit Click on: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / Run Delete On the right of 'c: / windows/notpa.exe / o = yes' Close Regedit, restart to the MSDOS system to remove C: /Windows/NotPa.exe Note: Do not delete the true NotePad.exe notebook OK 10. BF Evolution V5.3.12 Clearing Trojans: Open Registry Regedit Click on: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CURRENTVERSION / RUN Delete (Default) = "" Close Regedit, restart your computer again. Win 11.84 - 0.92 2.21 0.8X version is running in Win95 / 98 0.9x or higher, running in Win95 / 98 and Winnt Software Customer - Server
The agreement is the same, so NT customers can black 95/98 infected machines, and Win95 / 98 customer black NT is infected with the system. To remove Trojans: First prepare a 98 boot disk, use it to enter the C: / Windows directory, use Attrib LibUpd ~ 1.exe -h command to let Trojan visible, then delete it. After taking the floppy disk, restart, enter 98, find: hkey_local_machine / software / microsoft / windows / currentversion / run / subkey WinLibupdate = "c: /windows/libupdate.exe -hide" to delete this subkey . 12. BLA V1.0 - 5.03 Remove Trojans: Open Registry Regedit Click on: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CURRENTVERSION / RUN Delete SystemDoor = "C: /Windows/system/mprdll.exe" Off Regedit, restart your computer. Find C: /Windows/System/MPrdll.exe and C: /Windows/system/rundll.exe Note: Do not delete the C: /Windows/rundll.exe correct file. And delete two files. OK 13. Bladerunner Clear Trojans: Open Registry Regedit Click on: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / Run You can find system-tray = "c: /something/something.exe" on the right side of the right side may be any Things, then you don't need to delete it, because the Trojan will automatically add it immediately, you need to write down the name of the Trojan and the directory, then return it to MS-DOS, find this Trojan file and delete it. Restart your computer, then repeat the first step, find the Trojan file in the registry and delete this button. 14. Bobo v1.0 - 2.0 Clear Trojan v1.0 Open the Registry Regedit Click the catalog to: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / Run delete DirrectLibrarySupport the right = "C: /WINDOWS/SYSTEM/Dllclient.exe" Close Regedit, restart your computer. Del C: /Windows/system/dllclient.exe OK Clear Trojans V2.0 Open Registry Regedit Click to: HKEY_USER / .DEFAULT / SOFTWARE / MIRABILIS / ICQ / Agent / Apps / ICQ Accel / ICQ Accel is a "imaginary" The primary key, select the ICQ Accel primary key and delete it. Restart your computer. OK 15. Brainspy Vbeta Steps to Clear Trojans: Open Registry Regedit Click on: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / Run Right ??? = "C: / Windows / System / Brainspy .exe" ??? The label selection is invisible.
Close Regedit, restart your computer to find delete C: / windows / system / brainspy .exe ok 16. Cain and Abel v1.50 - 1.51 This is a password Trojan enters the MS-DOS method to find C: /Windows/msabel32.exe and Delete it. OK 17. CANASSON Clear Trojan step: Open the win.ini file to find c: /msie5.exe, remove the full primary key to save the Win.ini restart computer Delete C: /msie5.exe Trojan file OK 18. Chupachbra Clear Trojan step: Open Win.ini file [Windows] There are two rows run = winprot.exe load = WinProt.exe delete WinProt.exe run = load = save Win.ini, open the registry regedit Click on: hkey_local_machine / Software / Microsoft / Windows / CURRENTVERSION / RUN Delete the 'System Protect' = WinProt.exe on the right side Restart Windows Find C: / Windows / System / WinProt.exe and deletes. OK 19. Coma v1.09 Steps to remove Trojans: Open Registry Regedit Click on: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CURRENTVERSION / RUN Delete 'Runtime' = C: /Windows/msgsrv36.exe Restart Windows Find Go to C: / Windows / Msgsrv36.exe, and delete. OK 20. Control Clear Trojan Steps: Open Registry Regedit Click on: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / Run Delete Load MSCHV DRV.EXE Save REGEDIT, restart Windows finds C: /Windows/system/mschv.exe, and deletes. OK 21. Dark Shadow Trojan removal steps: Open the Registry Regedit Click the catalog to: HKEY_LOCAL_MACHINE / SOFTWARE / MicroSoft / Windows / CurrentVersion / RunServices delete winfunctions the right = "winfunctions.exe" Save Regedit, restart Windows looks to C: / Windows / System / Winfunctions.exe, and delete.
OK 22. Deepthroat V1.0 - 3.1 MOD (Foreplay) Clear Trojans: Open Registry Regedit Click on: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / Run version 1.0 Delete the right item 'system32' = C: /Windows/system32.exe version 2.0-3.1 Delete the right project 'systemtray' = 'systemtray' Save regedit, restart Windows version 1.0 Delete C: /Windows/system32.exe version 2.0-3.1 Delete C: / Windows / System / SYSTRAY.EXE OK 23. Delta Source V0.5 - 0.7 Clear Trojans: Open Registry Regedit Click on: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / Run Delete Project: DS Admin Tool = C: /TEMPSERVER.EXE Save Regedit, restart Windows to find C: /TEMPSERVER.EXE and delete it. OK 24. DER SPAEHER V3 Clear Trojans: Open Registry Regedit Click on: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / Run Delete the right of the right: Explore = "c: /windows/system/dkbdll.exe" Save Regedit, restart Windows Delete C: /Windows/system/dkbdll.exe Trojan file. OK 25. Doly V1.1 - V1.7 (SE) Clear Trojans V1.1-V1.5 version: These Trojans version of Trojans are placed in three, add two registration projects, but also to Win.ini project. First, enter the MS-DOS mode, delete three Trojans, but V1.35 has multiple Trojans MDM.EXE. Remove all of the following: c: /windows/system/tesk.sys c: / windows / start menu / programs / startup / mstesk.exe c: / program files / mstesk.exe C: / Program files / mdm.exe Restart Windows. Next, open the win.ini file to find [Windows] below load = c: /windows/system/tessk.exe project, delete the path, change to load = save the Win.ini file.
Finally, modify the registry Regedit Locate the following two items and delete them HKEY_CURRENT_USER / Software / Microsoft / Windows / CurrentVersion / Run Ms tesk = "C: / Program Files / MStesk.exe" and HKEY_USER / .Default / Software / Microsoft / Windows / CURRENTVERSION / RUN MS TESK = "C: / Program Files / Mstesk.exe" then looking to HKEY_CURRENT_USER / SOFTWARE / SS This group is a total parameter selection and setting of the Trojan, deletes this SS group All projects. Close the saved regedit. There is also an open C: /autoexec.bat file, delete @echo off copy c: /sys.lon c: / windows / startMenu / startup items / del c: /win.reg Turn off Save Autoexec.bat. OK Clear Trojans V1.6: When the Trojan is running, it will not be able to close through the normal operation of 98, and can only reset. The thorough removal step is as follows: 1. Open Control Panel - Add Delete Programs - Delete Memory Manager 3.0, which is a Trojan, but it does not delete the EXE file of Trojans. 2. After starting with a 98 or DOS boot disk (with the reset button), transfer to C: /, edit AutoExec. BAT, remove the following: @echo off copy c: /sys.lon c: /windows/startm ~ 1/programs/startup/mdm.exe del c: /win.reg Save AutoExec. After the BAT file and return DOS, remove Trojan files in the C: / root directory: del sys.lon del windows / startm ~ 1 / programs / startup / mdm.exe del progra ~ 1 / mdm.exe 3. Take the floppy disk to restart, after entering 98, delete the Memory Manager directory under the C: / Program files / directory. Clear Trojans V1.7: First, open the c: /autoexec.bat file, remove @echo off copy c: /sys.lon c: /windows/startm ~ 1/programs/startup/mdm.exe del C: / win .reg Close Save Autoexec.bat and open the registry regedit Click on the directory to: hkey_local_machine / software / microsoft / windows / currentversion / run Find the C: /Windows/system/mdm.exe path and remove this item to: HKEY_USER /. DEFAULT / SOFTWARE / MARABILIS / ICQ / Agent / Apps / Find the "C: /Windows/System/kernal32.exe" path and remove this item to close Save Regedit. Restart Windows.
Finally, remove the following Trojan: c: /sys.lon c: /iecookie.exe C: / Windows / Start Menu / Programs / Startup / MDM.EXE C: / Program Files / MDM.EXE C: / Windows / System / MDM.EXE C: /WINDOWS/System/kernal32.exe Note: Kernal32 is A OK 26. Donald Dick V1.52 - 1.55 Clear Trojan V1.52-1.53 Version: Open Registry Regedit Click on: HKEY_LOCAL_MACHINE / SYSTEM / CURRENTCONTROLSET / Services / VXD / VMLDIR / Delete Items: staticvxd = "Vmldir.vxd" Close Save regedit, restart Windows Delete C: /Windows/system/vmldir.vxd OK Clear Trojan V1.54-1.55 version: These two The version is just the default file name, and the other is the same, and the VMLDIR.vxd can be changed to INTLD.VDX. 27. DRAT V1.0 - 3.0B Remove Trojans: Open Registry Regedit Click on: HKEY_CLASS_ROOT / EXEFILE / Shell / Open / Command Location @ = shell32 / "% 1 /"% * Change it to @ = " % 1 "% * Close the save regedit, restart Windows. Find c: / windows / lower shell32. * File and delete it.
OK 28. Eclipse 2000 Steps to Clear Trojans: Open Registry Regedit Click on: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / Run / Delete Project: Bybt = "C: /Windows/system/eclipse2000.exe" Click catalog to: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RunServices / delete the right of the item: cksys = "c: / windows / system / could be anything .exe" Close save Regedit, restart Windows to find the Trojan file eclipse2000.exe And delete 29. Eclypse v1.0 Clear Trojan step: Open Registry Regedit Click on: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / Run / Delete Project: RNAApp = "C: / Windows / System / RMAApp "Close the save regedit, restart Windows Delete C: /Windows/system/rmaapp.exe Note: Do not delete RNAAPP.EXE OK 30. EXECUTER V1 Steps to clear Trojans: Open Registry Regedit Click on: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN / Items on the right look up "C: /Windows/sexec.exe" and deletes. Turn off the regedit, restart Windows to remove Trojan files accordingly. OK 31. FakeftP Beta Clear Trojans: Open Registry Regedit Click on: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / Run / Delete Project: Rundll32 = Rundll3.tww / h Close Save Regedit, restart Windows to find The three files under the C: / Windows / folder and remove them Rundll3.bat - 9x.reg - NT.REG OK 32. FORCED Entry Steps to clear Trojans: Open Registry Regedit Click on: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / Run / Remove the right item: MicrosoftRegistration32 = "c: / somepath /trojanhrs.exe" Close Save regedit, restart Windows due to the path easy to change, simply find Trojanhrs.exe and delete it.
33. GATCRASHER V1.0 - 1.2 Clear Trojans V1.0: Open Registry Regedit Click on: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / Run / Delete Out of Item: Explore = 'C: /Windows/Explore.exe 'Turn off the regedit, restart Windows and then delete the corresponding Trojan. OK Clear Trojan V1.1: Open Registry Regedit Click on: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / Run / Remove Project: INET = 'Explore.exe' Turn off Save Regedit, restart Windows and then find the corresponding Trojan and delete. OK Clear Trojans V1.2: Open Registry Regedit Click on: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / Run / Delete Project: Command = 'c: /windows/system.exe' Turn off Regedit, restart Windows then find the corresponding Trojan and delete it. OK 34. Girlfriend V1.3X (Including Patch 1 and 2) Clear Trojans: Open Registry Regedit Click on: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / Run / Delete Project: Windll.exe = "C : /Windows/windll.exe "regedit also saves server data HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / General Delete General Item Title Turn off Save Regedit, restart Windows and find the corresponding Trojan, and delete. OK 35. Golden Retreiver v1.1b Clear Trojan step: Open Registry Regedit Click on: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / Run / Delete Project: Task Manager = "C: /MStask.exe" Off Save regedit, restart Windows and find the corresponding Trojan and delete. OK 36. Hack`a`tack 1.0 - 2000 Clear Trojans V1.0-1.2: Open Registry Regedit Click on: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / Run / Delete Project: Explorer32 = "C: / Windows / Expl32.exe "Close Save Regedit, restart Windows and find the corresponding Trojan and delete.
OK Clear Trojan v2000: Open the Registry Regedit Click the catalog to: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / Run / delete items on the right: Configuration Wizard = c: /windows/cfgwiz32.exe Close Save Regedit, restart Windows Delete c : /Windows/cfgwiz32.exe OK 37. Hack99 Keylogger Clear Trojan Steps: Open Registry Regedit Click on: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / Run / Remove Project: HKeylog = "C: / Windows / System / HKeylog.exe "Close Save Regedit, restart Windows Delete C: /Windows/system/hkeylog.exe OK 38. HostControl v1.0 Clear Trojan step: Open Registry Regedit Click on: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / Run / Delete the right of the right: regclean = "c: /windows/INF/Regcle32.exe" Close Save Regedit, restart Windows Delete C: /Windows/INF/Regcle32.exe OK 39. HVL Rat V5. 30 Clear Trojans: Open Registry Regedit Click on: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CURRENTVERSION / RUN / Delete Project: Explorer = "C: /Windows/system/msgsvr16.exe" Close Save Regedit, Re-Save Start Windows Delete C: /Windows/system/msgsvr16.exe OK 40. IK97 V1.2 Clear Trojan Steps: Open Registry Regedit Click on: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CURRENTVERSION / RUN / Delete the right of the right side: IK = 'c: /progra ~ 1/ik/ik.exe' Close Save regedit, restart Windows Delete C: / Program Files / IK / IK.EXE OK 41. Incommand V1.0 - 1.5 Clear Trojan step: Open registration Table regedit Click on: hkey_local_machine / software / microsoft / windows / currentversion / run / find the right of the right side: advancedSettings = * Note: * Indicates that the hippo is stored and the file name, and then remove this button. Close the saved regedit, restart Windows to remove Trojans with the file name as the Trojan path you just recorded.
42. IndocTrination v0.1 - step v0.11 remove Trojan: Open the Registry Regedit Click the catalog to: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / Run / HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RunServices / HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RunOnce / HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RunServicesOnce / each title includes Msgsrv16 = "Msgsrv16" project remove each item Close save Regedit, restart Windows delete C: / windows / system /msgserv16.exe ok 43. INET V2.0 - 2.0N Clear Trojan step: Open Registry Regedit Click on: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / Run / Delete Project: Explorer = "C: / Windows / System / Inet.exe "Close Save Regedit, restart Windows Delete" C: /Windows/system/inet.exe "Delete" C: /Windows/system/Inet.dll "OK 44. Infector V1.0 - 1.42 Steps to remove Trojans: Open the system.ini file to find the shell = Explorer.exe c: /path/to/trojan.exe project to: Shell = Explorer.exe Save Close System.ini file, restart Windows Delete C: / Path /TO/trojan.exe ok 45. Inikiller v1.2 - 3.2 Pro steping Trojan step: Open Registry Regedit Click on: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / Run / Delete Right Project: Explore = "C: /Windows/bad.exe" Close Save regedit, restart Windows Delete C: /Windows/bad.exe OK 46. Intruder Clear Trojan step: Open Registry Regedit Click on: HKEY_LOCAL_MACHINE / Software / Microsoft / Windows / CurrentVersion / Run / Remove the right item: ppmodule1 = 'ppmod1.sys' Turn off the regedit, restart Windows Delete C: / Windows / System / PPMOD1.SYS Delete C: / Windows / System / PPMOD2. SYS OK 47. IRC3 Clear Trojans: Open the win.ini file to find the load = closew project, change to: load = Save Win.ini, restart Windows Find these two files' rundlls.exe ',' closew.bat 'And delete them.
OK 48. KAOS V1.1 - 1.3 Clearing Trojans: Open Registry Regedit Click on: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / Run / Delete Project: SYS = "C: /Windows/Shell32.exe "Turn off the regedit, restart Windows Delete C: /Windows/Shell32.exe OK 49. KHE SANH V2.0 Clear Trojan step: Open Registry Regedit Click on: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN / Delete the right one of the items: tboot0001 = "c: /windows/system/trjp.exe" Close Save regedit, restart Windows Delete C: /Windows/system/trjp.exe OK 50. Kuang Logger Steps to Clear Trojans: Open Registry Regedit Click on: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CURRENTVERSION / RUN / Delete Right Item: K2Logas.task = "C: /Windows/system/k2logas.exe" Close Save Regedit, restart Windows Delete C: / Windows /System/k2logas.exe ok 51. Kuang Original - 0.34 Clear Trojan V Original Version: Open Registry Regedit Click on: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / Run / Remove Project: Temp $ 1.task = " C: /Windows/system/temp (/ windows/System Clear Trojans V 0.20-0.21 version: Click on: hkey_local_machine / software / microsoft / windows / currentversion / run / delete the right of the right side: k2ps.task = "C: / Windows /system/k2ps.exe "Clear Trojan V 0.30-0.34 version: Click on the directory to: HK EY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN / Delete Right Project: K2PS_FULL.TASK = "C: /Windows/system/k2ps_full.exe" Close Save Regedit, restart Windows lookup the corresponding Trojan, and delete.
OK 52. Logger Clear Trojans: Open Registry Regedit Click on: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / Run / Delete the right of the right side: ??? = "c: /windows/system/logged.exe" Turn off the regedit, restart Windows Delete C: / Windows / System / Logged.exe OK 53. Magic HORSE Clear Trojan step: Open Registry Regedit Click on: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / Run / Delete Right Project: SpoolerService = "c: /windows/spoolsrv.exe" Close Save regedit, restart Windows Delete C: /Windows/spoolsrv.exe OK 54. Malicious Clear Trojan step: Open Registry Regedit Click on: HKEY_USERS / .Default / Software / Microsoft / Windows / CurrentVersion / Policies / delete the right of the five projects: DisableRegistryTools NoRun NoFind NoDesktop NoClose Close save Regedit, restart step Windows OK 55. Masters Paradise remove Trojan: open the registry Regedit click the catalog to: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / Run / delete the right of the item: SYSEDIT = c: / windows / sysedit.exe HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RunServices delete the item on the right: Explorer = c: / .. .... / agent.exe Turn off the regedit, restart Windows to find the Trojan and delete them. Note: c: / windows / system / below the SYSEDIT.EXE file is not 19kb, if not explained to be infected with Trojans, delete it.
OK 56. Matrix V1.0 - 2.0 Clearing Trojans: Open Registry Regedit Click on: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / Run / Delete Out of Item: ??? = "C: / Windows / WinCFG "Close the step of saving regedit, restarting Windows Delete C: /Windows/wincfg.exe OK 57. MBK Clear Trojan step: Open Registry Regedit Click on: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / Run / Find Delete the right on the right: Explorer = "" Behind "Mbt.exe" Close Save regedit, restart Windows to find Mbt.exe and remove OK 58. Millenium V1.0 - 2.0 Clear Trojan step: Open Registry Regedit Click on the directory to : HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / Run / delete items on the right: Millenium = "C: /windows/system/reg66.exe" Close save Regedit, restart Windows delete C: /windows/system/reg66.exe OK 59. MINE Clear Trojan step: Open Registry Regedit Click on: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / Run / Delete Project: Windows = 'c: /msdos98.exe' Turn off Regedit, restart Windows Delete C: /MSDOS98.EXE Opens the win.ini file to find Run = C: /Windows/uninstallms.exe Change to: Run = Close Win.ini, restart Windows del C: /msdos98.exe del C: / Windows / Uninst ~ 1.exe del C: /Windows/system/mine.exe ok 60. Mosucker Steps to clear Trojans: Open system.ini file to find SHE LL = Explorer.exe unin0686.exe Change to: shell = Explorer.exe Turn off System.ini, restart Windows Delete C: /Windows/unin0686.exe OK 71. Progenic Password
Thief / Keylogger V1.0 Clear Trojan Steps: Open Registry Regedit Click on: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / Run / Delete Right Items: PWT = "C: /Windows/system/pwt.exe" Turn off the regedit, restart Windows Delete C: /Windows/system/pwt.exe OK 72. Progenic v1.0 -3.0 Clear Trojan step: Open Registry Regedit Click on: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / Run / Delete Project: Scandisk = "C: /Windows/ScandiskVr.exe" Close Save Regedit, restart Windows Delete C: /Windows/scandiskvr.exe OK 73. Prosiak Beta - 0.70 B5 Clear Trojan step: Open registration table Regedit click the catalog to: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RunServices / delete items on the right: Microsoft DLL Loader = "windll32.exe" Close save Regedit, restart Windows delete C: / WINDOWS / windll32.exe OK 74 RETRIEVE V1.3 Clear Trojan step: Open Registry Regedit Click on: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / Run / Delete Project: Microsoft Access = "C: /Windows/access.exe" Turns Regedit, restart Windows Delete C: /Windows/access.exe OK 75. REVENGER V1.0 - 1.5 Clear Trojans: Open Registry Regedit Click on: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / Run / Delete Right Side item: appname = "c: /.../ Server.exe" Close Save regedit, restart Windows to find the corresponding Trojan server.exe in C: / Windows, and remove OK 76. Ripper Clear Trojan step: Open the System.ini file to change shell = explorer.exe sysrunt.exe to shell = Explorer.exe Turn SYSTEM.INI, restart Windows to find the corresponding Trojan SysRunt.exe in C: / Windows, and remove OK 77. Satans Back Door v1.0 Clear Trojan step: Open Registry Regedit Click on: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RunServices / Delete Projects on the right:
Sysprot Protection = "C: /Windows/sysprot.exe" Close Save Regedit, restart Windows Delete C: /Windows/sysprot.exe OK 78. Schwindler v1.82 Steps to clear Trojans: Open Registry Regedit Click on: HKEY_LOCAL_MACHINE / Software / Microsoft / Windows / CurrentVersion / Run / Remove the right item: user.exe = "c: /windows/user.exe" Close Save regedit, restart Windows Delete C: /Windows/user.exe OK 79. SETUP Trojan (SSHARE) MOD SMALL Share This sharing hidden C-Trojan Steps: Open Registry Regedit Click on: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / Network / LanMan / Select 'C $' Project, and all delete close saver regedit, restart Windows OK 80. ShadowPhy V2.12.38 - 2.X Clear Trojan step: Open Registry Regedit Click on: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / Run / Delete Right Project: Winzipp = "C: /Windows/system/winzipp.exe / nomsg" or winzip = "c: /windows/system/winzip.exe / nomsg" Close Save regedit, restart Windows Delete C: / Windows / WinZipp . EXE or C: / Windows / Winzip.exe OK 81. Share All Steps to clear Trojans: Open Registry Regedit Click on: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / Network / Lanman / Here you will see all Shared your hard drive symbols in Trojans, remove them one by one.
82. SHITHEAP Clear Trojans: Open Registry Regedit Click on: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RunServices / Delete Right Items: Recycle-Bin = "C: /Windows/system/recycle-bin.exe "Or Recycle-Bin =" C: /Windows/system.exe "Close Save Regedit, restart Windows Delete C: /Windows/System/recycle-bin.exe or C: /Windows/system.exe OK 83. SNID V1 - 2 Clear Trojans: Open Registry Regedit Click on: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / Run / Delete Project: System-TRAY = 'c: /Windows/Tem # @ 0' C: /Windows/Tem # 0 0: 'Turn off save regedit , Restart Windows Delete C: /Windows/temp $01.exe OK 84. SoftWarst Steps to Clear Trojans: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / Run / Delete Item: NetApp = C: /Windows/system/winserv.exe Close Save Regedit, restart Windows Delete C: /Windows/system/winserv.exe OK 85. Spirit 2000 Beta - V1.2 (Fixed) Clear Trojans V Beta version: Open registry Regedit Click on: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CURRENTVERSION / RUN / Delete Right Project: Internet = "C: /Windows/netip.exe" Close Save RegedIt Open Win.ini file to find Run = C: / Windows /Netip.exe change to: run = Turn off Win.ini, restart Windows Delete C: / Window S / Netip.exe and C: /Windows/netip.exe OK Clear Trojans V 1.2 version: Open Registry Regedit Click on: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / Run / Delete Project: SystemTray = "C : /Windows/Windown.exe "Close Save Regedit, restart Windows Delete C: /Windows/Windown.exe OK Clear Trojan V 1.2 (Fixed) version: Open Registry Regedit Click on: HKEY_LOCAL_MACHINE / Software / Microsoft / Windows / CurrentVersion / Run / Remove the right item: Server 1.2.exe = "c: / windows / server 1.2.exe" Close Save Regedit,
Restart Windows Delete C: / Windows / Server 1.2.exe OK 86. Stealth V2.0 - 2.16 Clear Trojans: Open Registry Regedit Click on: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / Run / Delete Right Project: WinProtect System = "C: /Windows/WinProtecte.exe Close Save Regedit, restart Windows Delete C: /Windows/WinProtecte.exe OK 87. Subseven - Introduction Clear Trojan V1.0 - 1.1: Open Registry Regedit Click on Table to: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / Run / delete items on the right: SystemTrayIcon = "C: /WINDOWS/SysTrayIcon.Exe" Close save Regedit, restart Windows delete C: /WINDOWS/SysTrayIcon.Exe OK Clear Trojan V1.3 - 1.4 - 1.5: Open the win.ini file to find Run = NODLL Change to Run = Close Win.ini, restart Windows Delete C: /Windows/nodll.exe OK Clear Trojan V1.6: Open Registry Regedit click the catalog to: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / Run / delete items on the right: SystemTray = "SysTray.Exe" Close save Regedit, restart Windows delete C: /windows/systray.exe OK Clear Trojan v1. 7: Open the registry regedit Click on the directory to: hkey_local_machine / software / microsoft / windows / currentversion / runservices / find the right side item: c: /windows/kernel16.dl, and remove the shutdown to save the regedit, restart Windows Delete C: / Windows / kernel16.dl ok Clear Troja V 1.8: Open the Registry Regedit Click the catalog to: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / Run and HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RunServices / find the right item: c:. /Windows/system.ini, And delete the closed saved regedit. Open the win.ini file to find Run = kernel16.dl to change to Run = Turn off Win.ini.
Open the system.ini file to find shell = expener.exe kernel32.dl Change to Shell = Explorer.exe Turn off System.ini, restart Windows Delete C: /Windows/kernel16.dl OK Clear Trojan V1.9 - 1.9B: open the registry Regedit click the catalog to: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / Run and HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RunServices / delete items on the right: RegistryScan = "rundll16.exe" Close save Regedit, restart Windows Delete C: /Windows/rundll16.exe OK Clear Trojan V2.0: Open System.ini file Find shell = expener.exe Trojanname.exe Change to Shell = Explorer.exe Turn SYSTEM.INI, restart Windows Delete C : /Windows/rundll16.exe OK Clear Trojans V2.1 - 2.1 Gold Substealth- 2.1.3 MOD 2.1.3 MUIE 2.1 Bonus: Open Registry Regedit Click on: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / Run and HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / Runservices / Delete Items: WinLoader = MSREXE.EXE HKEY_CLASES_ROOT / EXEFILE / Shell / Open / Command Change the item on the right to: @ = "/"% 1 / "% "Close the saved regedit. Open the win.ini file to find Run = msRexe.exe and load = msrexe.exe Change to Run = LOAD = Turn off Win.ini. Open the System.ini file to find shell = expenented.exe msrexe.exe Change to Shell = Explorer.exe Turn off System.ini, restart Windows Delete C: / Windows / MSREXE.EXE C: /WINDOWS/System/Systray.dll OK Clear Trojan V2.2B1: Open Registry Regedit Click on: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / Run and Delete Items: Loader = "C: / Windows / System / ***" Note: Load The device and file name are the closing of the arbitrary change to save the regedit. Open the win.ini file Change to Run = Turn off Win.ini.
Open the System.ini file Change to Shell = Explorer.exe Turn off System.ini, restart Windows Delete Corresponding Trojan OK 88. Telecommando 1.54 Clear Trojans: Open Registry Regedit Click on: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / Run / Delete Project: SystemApp = "odbc.exe" Close Save Regedit, restart Windows Delete C: / Windows / System / ODBC.EXE OK 89. The UnExplained Clear Trojan step: Open the registry Regedit click the catalog to: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / Run / delete items on the right: InetB00st = "C: /WINDOWS/TEMPINETB00ST.EXE" Close save Regedit, restart Windows delete C: /WINDOWS/TEMPINETB00ST.EXE OK 90. Thing V1.00 - 1.60 Clear Trojan V1.00-1.12: Click on: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN / Delete Out of Item: (Default) = "C: / Some / Path / Here / Thing.exe "There are also some items in: hkey_local_machine / system / currentControlSet / Control / SessionManager / KNown16DLLS / Delete: WSASRV.EXE =" WSASRV.exe "Turns Regedit, restart Windows Delete C: / Some / PATH / Here / Thing.exe OK Clear Trojans V 1.20 version: Enter MS_DOS Mode: DEL WINSPC13.EXE DEL MS097.EXE Opens SHELL = Explorer.exe MS097.exe to: Shell = Explorer.exe Close Save System.ini and restart Windows OK Clear Trojan V1.50: Click on the directory to: hkey_local_machine / software / microsoft / windows / currentversion / run / this project path and file name is random change, look at the suspicious file path, delete it. Close the saved regedit.
Open the system.ini file to find shell = Explorer.exe is a Trojan file change to: shell = explorer.exe Close Save System.ini, restart Windows Delete the corresponding Trojan file OK Clear Trojan V1.50 version: Enter the MS_DOS method: DEL WINSPC13.EXE DEL MS097.EXE Opens SYSTEM.INI file to find shell = Explorer.exe later is the Trojan file change to: shell = expener.exe Turn off System.ini, restart Windows Delete the corresponding Trojan file Ok 91. Transmission SCOUNT V1.1 - 1.2 Clear Trojan step: Open Registry Regedit Click on: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / Run / Delete Project: Kernel16 "= C: /Windows/kernel16.exe Close Save Regedit , Restart Windows Delete C: /Windows/kernel16.exe OK 92. Trinoo Clear Trojan Steps: Open Registry Regedit Click on: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / Run / Delete Project: System Services = Service.exe Close Save Regedit, restart Windows Delete C: /Windows/System/service.exe OK 93. Trojan Cow v1.0 Clear Trojan step: Open Registry Regedit Click on: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / Run / Remove Project: SysWindow = "C: /Windows/SysWindow.exe" Close Save Regedit, restart Windows Delete C: /Windows/sysWindow.exe OK 94. Tryit Clear Trojan step: Open Registry Regedit Click on the directory to: hkey_local_machine / software / microsoft / window S / CURRENTVERSION / RUN / Delete the right item: RC5DEC = C: / Program Files / Internet Explorer / _. EXE -GUISTART Turn off the regedit, restart Windows Delete C: / Program Files / Internet Explorer / _. EXE OK 95. Vampire V1.0 - 1.2 Clear Trojans: Open Registry Regedit Click on: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / Run / Remove Project: Sockets = "C: /Windows/system/sosckets.exe" Turn off the regedit, restart Windows Delete C: /Windows/system/sockets.exe OK
96. WARTROJAN V1.0 - 2.0 Clearing Trojans: Open Registry Regedit Click on: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / Run / Delete Item: kernel32 = "c: /somePath/server.exe" Close Save regedit, restart Windows Delete C: /SOMEPath/server.exe OK 97. WCRAT V1.2B Clear Trojan Steps: Open Registry Regedit Click on: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / Run / Delete Right Project: MS Windows System Explorer = "C: /Windows/SYSExplor.exe" Close Save Regedit, restart Windows Delete C: /Windows/SySexplor.exe OK 98. WebEX (v1.2, 1.3, and 1.4) Clear Trojan Step: Open Registry Regedit Click on: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CURRENTVERSION / RUN / Delete Right Project: Rundl32 = "C: / Windows / System / Task_bar" Close Save Regedit, restart Windows Delete C: / windows/system/task_bar.exe and c: /windows/system/msinet.ocx OK 99. WinCrash V2 Clear Trojan step: Open Registry Regedit Click on: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / Run / Delete On the right: WinManager = "c: /windows/server.exe" Close Save regedit Open Win.ini file to find Run = C: /Windows/server.exe Change to: Run = Save Win.ini, restart Windows Delete C: /Windows/server.exe OK 100. WinCrash Clear Trojans: Open Registry regedit Click on: hkey_local_machine / software / microsoft / windows / currentversion / run / remove the right item: msmanager = "server.exe" Close Save regedit, restart Windows Delete C: / Windows / System / Server.exe OK 101. Xanadu v1.1 Clear Trojans: Open Registry Regedit Click on: HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / Run / Delete Project: Setup = "C: /SOMEPath/setup.exe" Close Save Regedit, restart Windows Delete C: /SOMEPath/setup.exe OK