104 kinds of removal Trojans complete Raiders 104 clear Trojans complete Raiders
【简】
Many newcomers know more about security issues, and the computer in Trojan horses don't know how to clear. Although there are many software that clear the Trojan horse, you can automatically remove Trojans. But you don't know how the Trojan is running in the computer. If you read this article, you will understand some of the principles of Trojan.
Many newcomers know more about security issues, and the computer in Trojan horses don't know how to clear. Although there are many software that clear the Trojan horse, you can automatically remove Trojans. But you don't know how the Trojan is running in the computer. If you read this article, you will understand some of the principles of Trojan.
1. Ice V1.1 V2.2
Ice is the best Trojan in China
Clear Trojan V1.1
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN
Find the following two paths and delete
"C: / windows / system / kernel32.exe"
"C: / windows / system / sysExplr.exe"
Close Regedit
Restart to MSDOS
Delete C: / Windows / System / Kernel32.exe and C: / Windows / System / Sysexplr.exe Trojan
Restart. OK
Clear Trojan V2.2
Server programs, path users can be freely defined, and the key names written in the registry can also be defined.
Therefore, it cannot be clearly stated.
You can check the registry and delete the suspicious file path.
Restart to MSDOS
Delete Trojans corresponding to registry
Restart Windows. OK
2. ACID BATTERY V1.0
Steps to remove Trojans:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN
Delete Explorer = "C: /Windows/expiorer.exe" on the right
Close Regedit
Restart to MSDOS
Delete C: /Windows/expiorer.exe Trojan
Note: Do not delete the correct Explorer.exe program, there is only the difference between I and L between them.
Restart. OK
3. ACID Shiver V1.0 1.0MOD LMACID
Steps to remove Trojans:
Restart to MSDOS
Delete C: /Windows/msgsvr16.exe
Then return to the Windows system
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN
Delete Explorer = "C: /Windows/msgsvr16.exe" on the right
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RunServices
Delete Explorer = "C: /Windows/msgsvr16.exe" on the right
Close Regedit
Restart. OK
Restart to MSDOS
Delete C: /Windows/wintour.exe and return to the Windows system
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN
Delete Wintour = "C: /Windows/wintour.exe" on the right
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / Runservices Delete Wintour = "C: /Windows/WintOr.exe" on the right
Close Regedit
Restart. OK
4. AMBUSH
Steps to remove Trojans:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN /
Delete zka = "zcn32.exe" on the right
Close Regedit
Restart to MSDOS
Delete C: / Windows / ZCN32.exe
Restart. OK
5. AOL Trojan
Steps to remove Trojans:
Start to MSDoS
Delete C: / Command.exe (unable to cancel the implied property before delete)
Note: Do not delete true command.com files.
Delete C: / American ~ 1.0 / buddyl ~ 1.exe (unable to cancel the implied property before delete)
Delete C: / Windows / System / Norton ~ 1 / Regist ~ 1.exe (unable to cancel the file before deleting
Open Win.ini file
In [Windows], "Run =" and "LOAD =" are loaded with the path of Trojm Horse, and they must be cleared:
Run =
LOAD =
Save Win.ini
Also correct the registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN
Delete WinProfile = C: /command.exe on the right
Close Regedit, restart Windows. OK
6. Asylum V0.1, 0.1.1, 0.1.2, 0.1.3 mini 1.0, 1.1
Steps to remove Trojans:
Note: Trojan The default file name is WinCMP32.exe, but the program can change the file name at will.
We can remove Trojans according to the System.ini and Win.ini modified by Trojans.
Open system.ini file
There is a "shell = file name" below [boot]. The correct file name is Explorer.exe
If it is not "Explorer.exe", then that file is a Trojan, find it out, delete.
Save exit System.ini
Open Win.ini file
There is a run = below [Windows]
If you see = There is a path file name behind, you must delete it.
The correct thing should be Run = no.
= The back path file name is Trojan and looks out, delete it.
Save exit Win.ini.
OK
7. AttackFTP
Steps to remove Trojans:
Open Win.ini file
There is load = wscan.exe in [Windows]
Delete WSCAN.exe, correctly loading =
Save exit Win.ini.
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN
Remove the REMINDER = "wscan.exe / s"
Close Regedit, restart to the MSDOS system
Delete C: / Windows / System / WSCAN.exe
OK
8. BACK Construction 1.0 - 2.5 Clear Trojans:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN
Delete "C: /Windows/cmctl32.exe" on the right
Close Regedit, restart to the MSDOS system
Delete C: /Windows/cmctl32.exe
OK
9. Backdoor V2.00 - V2.03
Steps to remove Trojans:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN
Delete the 'c: / windows/notpa.exe / o = yes'
Close Regedit, restart to the MSDOS system
Delete C: /Windows/NotPa.exe
Note: Do not delete the real notepad.exe notebook programs
OK
10. BF evolution v5.3.12
Steps to remove Trojans:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN
Delete the right (default) = ""
Close Regedit, restart your computer again.
Will C: / Windows / System / .exe (Space EXE File)
OK
11. Bionet V0.84 - 0.92 2.21
0.8x version is running in Win95 / 98
0.9X or later has two software running on Win95 / 98 and Winnt
The customer-server protocol is the same, and thus NT customers can black 95/98 infected machines, and WIN95 / 98 customer can black NT is exactly the same.
Steps to remove Trojans:
First prepare a 98 boot disk, after starting, enter the c: / windows directory, use attrib libupd ~ 1.exe -h
Command Let Trojan visible and then delete it.
After taking the floppy disk, restart, enter 98, find it in the registry:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN /
Sub keys WinLibUpdate = "c: /windows/libupdate.exe -hide"
Remove this subkey.
12. BLA V1.0 - 5.03
Steps to remove Trojans:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN
Delete the systemdoor = "c: /windows/system/mprdll.exe" on the right
Close Regedit, restart your computer.
Find c: / windows/system/mprdll.exe and
C: /windows/system/rundll.exe
Note: Do not delete the C: /Windows/rundll.exe correct file.
And delete two files.
OK
13. Bladerunner
Steps to remove Trojans:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN
You can find system-tray = "c: /something/something.exe"
The path on the right may be anything, then you don't need to delete it, because the Trojan will automatically add it immediately, you need to write down the name and directory of the Trojan, then return it to MS-DOS, find this Trojan file and delete Drop.
Restart your computer, then repeat the first step, find the Trojan file in the registry and delete this button.
14. BOBO V1.0 - 2.0
Clear Trojan V1.0
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN
Remove the right side DirRectLibrarySupport = "c: /windows/system/dllclient.exe"
Close Regedit, restart your computer.
Del C: /Windows/system/dllclient.exe
OK
Clear Trojans V2.0
Open registry regedit
Click on the directory to:
HKEY_USER / .DEFAULT / SOFTWARE / MIRABILIS / ICQ / Agent / Apps / ICQ Accel /
ICQ Accel is a "imaginary" primary key, select the ICQ Accel primary key and remove it.
Restart your computer. OK
15. Brainspy Vbeta
Steps to remove Trojans:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN
Is there ??? = "c: / windows / system / brainspy .exe"
??? Tag election is invisible.
Close Regedit, restart your computer
Find delete C: / Windows / System / Brainspy .exe
OK
16. Cain and Abel v1.50 - 1.51
This is a password trumpet
Enter MS-DOS Way
Find c: / windows/msabel32.exe
And delete it. OK
17. Canasson
Steps to remove Trojans:
Open Win.ini file
Find c: / msie5.exe, delete all primary keys
Save Win.ini
Restart your computer
Delete C: /Msie5.exe Trojan file
OK
18. Chupachbra
Steps to remove Trojans:
Open Win.ini file
[Windows] There are two rows below
Run = WinProt.exe
Load = WinProt.exe
Delete WinProt.exe
Run =
LOAD =
Save Win.ini, open the registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN
Delete the 'System Protect' = WinProt.exe on the right
Restart Windows
Find C: / Windows / System / WinProt.exe and delete.
OK
19. coma v1.09
Steps to remove Trojans:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN
Delete the 'Runtime' = C: /Windows/msgsrv36.exe on the right
Restart Windows
Find c: / windows / msgsrv36.exe and delete. OK
20. Control
Steps to remove Trojans:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN
Delete the right Load MSCHV DRV = C: /Windows/system/mschv.exe
Save regedit, restart Windows
Find C: /Windows/system/mschv.exe and delete.
OK
21. Dark Shadow
Steps to remove Trojans:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RunServices
Delete Winfunctions = "Winfunctions.exe" on the right
Save regedit, restart Windows
Find C: / Windows / System / WinFunctions.exe and delete.
OK
22. Deepthroat V1.0 - 3.1 MOD (Foreplay)
Steps to remove Trojans:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN
Version 1.0
Delete the right item 'system32' = C: /Windows/system32.exe
Version 2.0-3.1
Delete the right of the project 'systemtray' = 'systemtray.exe'
Save regedit, restart Windows
Version 1.0 Delete C: /Windows/system32.exe
Version 2.0-3.1
Delete C: /Windows/System/SYSTRAY.EXE
OK
23. Delta Source V0.5 - 0.7
Steps to remove Trojans:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN
Delete the right item: ds admin Tool = C: /TEMPSERVER.EXE
Save regedit, restart Windows
Find C: /TEMPSERVER.EXE and remove it.
OK
24. DER SPAEHER V3
Steps to remove Trojans:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN
Delete the item on the right: Explore = "c: /windows/system/dkbdll.exe"
Save regedit, restart Windows
Delete the C: /Windows/system/dkbdll.exe Trojan file.
OK
25. Doly v1.1 - v1.7 (se)
Clear Trojans V1.1-V1.5 version:
These Trojans version of Trojans are placed in three, add two registration projects, and increase to Win.ini projects.
First, enter the MS-DOS mode, delete three Trojans, but V1.35 has multiple Trojans MDM.EXE.
Remove all of the following: c: /windows/system/tessk.sys
C: / Windows / Start Menu / Programs / Startup / Mstesk.exe
C: / program files / mstesk.exe
C: / program files / mdm.exe
Restart Windows.
Next, open the win.ini file
Find [Windows] Load = C: /Windows/system/tessk.exe project, delete the path, change to load =
Save the Win.ini file.
Finally, modify the registry regedit
Find the following two items and delete them
HKEY_CURRENT_USER / SOFTWARE / Microsoft / Windows / CurrentVersion / Run
MS Tesk = "C: / Program Files / Mstesk.exe"
with
HKEY_USER / .DEFAULT / SOFTWARE / Microsoft / Windows / CurrentVersion / Run
MS Tesk = "C: / Program Files / Mstesk.exe"
Look for HKEY_CURRENT_USER / SOFTWARE / Microsoft / Windows / CurrentVersion / SS
This group is a total parameter selection and setting of the Trojan, deleting all items of this SS group.
Close the saved regedit.
There is also an open c: /autoexec.bat file, delete
@echo off copy c: /sys.lon C: / Windows / StartMenu / Startup items /
Del C: /WIN.REG
Turn off Autoexec.bat.
OK
Clear Trojans V1.6 version:
When the Trojan runs, it will not be able to close through the normal operation of 98, and only the reset button. The thorough removal step is as follows:
1. Open Control Panel - Add Delete Programs - Delete Memory Manager 3.0, which is a Trojan, but it does not delete the EXE file of Trojans.
2. After starting with a 98 or DOS boot disk (with the reset button), transfer to C: /, edit AutoExec. BAT, delete the following:
@echo off copy c: /sys.lon c: /windows/startm ~ 1/programs/startup/mdm.exe
Del C: /WIN.REG
Save AutoExec. After the BAT file and returns DOS, remove Troja files in the C: / root directory:
Del sys.lon
Del Windows / StartM ~ 1 / Programs / Startup / MDM.exe
Del Progra ~ 1 / MDM.EXE
3. Take the floppy disk to restart, after entering 98, delete the Memory Manager directory under the C: / Program files / directory.
Clear Trojans V1.7 version:
First, open the C: /autoexec.bat file, delete
@echo off copy c: /sys.lon c: /windows/startm ~ 1/programs/startup/mdm.exe
Del C: /WIN.REG
Turn off autoexec.bat
Then open the registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN
Find the C: /Windows/system/mdm.exe path and delete this project
Click on the directory to: HKEY_USER / .DEFAULT / SOFTWARE / MARABILIS / ICQ / Agent / Apps /
Find the "C: /Windows/system/kernal32.exe" path and delete this project
Close the saved regedit. Restart Windows.
Finally, delete the following Trojans:
C: /sys.lon
C: /iecookie.exe
C: / Windows / Start Menu / Programs / Startup / MDM.exe
C: / program files / mdm.exe
C: /Windows/system/mdm.exe
C: /Windows/system/kernal32.exe
Note: kernal32 is a
OK
26. Donald Dick V1.52 - 1.55
Clear Trojans V1.52-1.53 version:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SYSTEM / CURRENTCONTROLSET / SERVICES / VXD / VMLDIR /
Delete the right item: staticvxd = "vmldir.vxd"
Close Save Regedit, restart Windows
Delete C: /Windows/system/vmldir.vxd
OK
Clear Trojans V1.54-1.55 version:
These two versions are only different from the above version of the default file name, and others are the same.
Change VMLDIR.VXD to INTLD.VDX.
27. Drat V1.0 - 3.0B
Steps to remove Trojans:
Open registry regedit
Click on the directory to: hkey_classes_root / exec / shell / Open / COMMAND
Find @ = shell32 / "% 1 /"% change to @ = "% 1"% *
Turn off the regedit and restart Windows.
Find c: / windows / lower shell32. * File and delete it.
OK
28. Eclipse 2000
Steps to remove Trojans:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN /
Delete the item on the right: Bybt = "c: /windows/system/eclipse2000.exe"
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RunServices /
Delete the item on the right: cksys = "c: / windows / system / could be anything .exe"
Close Save Regedit, restart Windows
Find Eclipse2000.exe Trojan files and delete
29. Eclypse v1.0
Steps to remove Trojans:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN /
Delete the right item: RNAAPP = "C: /Windows/system/rmaapp.exe"
Close Save Regedit, restart Windows
Delete C: /Windows/system/rmaApp.exe Note: Do not delete RNAApp.exe
OK
30. EXECUTER V1
Steps to remove Trojans:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN /
Find "C: /Windows/Sexec.exe" and delete it.
Close Save Regedit, restart Windows
Remove Trojan files accordingly.
OK
31. FakeftP beta
Steps to remove Trojans:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN /
Delete the right item: rundll32 = rundll3.tww / h
Close Save Regedit, restart Windows
Find three files under the C: / Windows / folder and remove them
Rundll3.bat - 9x.reg - nt.reg
OK
32. FORCED Entry
Steps to remove Trojans:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN /
Delete the right item: MicrosoftRegistration32 = "c: / somepath /trojanhrs.exe"
Close Save Regedit, restart Windows
Since the path is easy to change, simply find Trojanhrs.exe and delete it.
33. Gatecrasher v1.0 - 1.2
Clear Trojan V1.0:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN /
Delete the item on the right: Explore = 'c: /windows/explore.exe'
Close Save Regedit, restart Windows
Then, delete the corresponding Trojan.
OK
Clear Trojans V1.1:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN /
Delete the item on the right: inet = 'explore.exe'
Close Save Regedit, restart Windows
Then, find the corresponding Trojan and delete it.
OK
Clear Trojans V1.2:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN /
Delete the right item: Command = 'c: /windows/system.exe'
Close Save Regedit, restart Windows
Then, find the corresponding Trojan and delete it.
OK
34. Girlfriend V1.3X (include Patch 1 and 2)
Steps to remove Trojans:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN /
Delete the right item: Windll.exe = "C: /Windows/windll.exe"
Server data is also saved in regedit
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / General
Delete the General project title
Close Save Regedit, restart Windows
Then, find the corresponding Trojan and delete it.
OK
35. Golden Retreiver V1.1B
Steps to remove Trojans:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN /
Delete the right item: Task Manager = "c: /mstask.exe"
Close Save Regedit, restart Windows
Then, find the corresponding Trojan and delete it.
OK
36. Hack`a`tack 1.0 - 2000
Clear Trojans V1.0-1.2:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN /
Delete the right of the item: Explorer32 = "c: /windows/expl32.exe"
Close Save Regedit, restart Windows
Then, find the corresponding Trojan and delete it.
OK
Clear Trojans V2000:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN /
Delete the item on the right: configure wizard = C: /Windows/cfgwiz32.exe
Close Save Regedit, restart Windows
Delete C: /Windows/cfgwiz32.exe
OK
37. Hack99 Keylogger
Steps to remove Trojans:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN /
Delete the right item: hkeylog = "c: /windows/system/hkeylog.exe"
Close Save Regedit, restart Windows
Delete C: /Windows/system/hkeylog.exe
OK
38. HostControl v1.0
Steps to remove Trojans:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN /
Delete the right item: regclean = "c: /windows/inf/regcle32.exe"
Close Save Regedit, restart Windows
Delete C: /Windows/INF/Regcle32.exe
OK
39. HVL Rat V5.30
Steps to remove Trojans:
Open Registry Regedit Click on:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN /
Delete the right item: Explorer = "c: /windows/system/msgsvr16.exe"
Close Save Regedit, restart Windows
Delete C: /Windows/system/msgsvr16.exe
OK
40. IK97 V1.2
Steps to remove Trojans:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN /
Delete the right item: IK = 'c: /progra ~ 1/ik/ik.exe'
Close Save Regedit, restart Windows
Delete C: / Program Files / IK / IK.EXE
OK
41. Incommand v1.0 - 1.5
Steps to remove Trojans:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN /
Find the item on the right: AdvancedSettings = *
Note: * It is said that the hippo is stored with the file name, and then remove this button.
Close Save Regedit, restart Windows
Delete Trojans in accordance with the Trojan path and the file name just now.
42. IndocTrination V0.1 - V0.11
Steps to remove Trojans:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN /
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RunServices /
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RunOnce /
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RunServicesOnce /
Each title includes MSGSRV16 = "MSGSRV16" project
Delete each project
Close Save Regedit, restart Windows
Delete C: /Windows/system/msgServ16.exe
OK
43. INET V2.0 - 2.0N
Steps to remove Trojans:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN /
Delete the right of the item: Explorer = "c: /windows/system/inet.exe"
Close Save Regedit, restart Windows
Delete "C: /Windows/system/inet.exe"
Delete "C: /Windows/system/inet.dll"
OK
44. Infector v1.0 - 1.42
Steps to remove Trojans:
Open system.ini file
Find shell = Explorer.exe C: /Path/to/trojan.exe project
Change to: shell = Explorer.exe Saves the system.ini file, restart Windows
Delete C: /Path/to/trojan.exe
OK
45. INIKILLER V1.2 - 3.2 Pro
Steps to remove Trojans:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN /
Delete the item on the right: Explore = "C: /Windows/bad.exe"
Close Save Regedit, restart Windows
Delete C: /Windows/bad.exe
OK
46. Intruder
Steps to remove Trojans:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN /
Delete the right item: ppmodule1 = 'ppmod1.sys'
Close Save Regedit, restart Windows
Delete C: / Windows / System / PPMOD1.SYS
Delete C: / Windows / System / PPMOD2.SYS
OK
47. IRC3
Steps to remove Trojans:
Open Win.ini file
Find the load = closew project, change to: load =
Save Win.ini, restart Windows
Find these two files 'rundlls.exe', 'closew.bat'
And delete them.
OK
48. Kaos v1.1 - 1.3
Steps to remove Trojans:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN /
Delete the right item: sys = "c: /windows/shell32.exe"
Close Save Regedit, restart Windows
Delete C: /Windows/Shell32.exe
OK
49. KHE SANH V2.0
Steps to remove Trojans:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN /
Delete the right item: tboot0001 = "c: /windows/system/trjp.exe"
Close Save Regedit, restart Windows
Delete C: /Windows/system/trjp.exe
OK
50. Kuang Logger
Steps to remove Trojans:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN /
Delete the right item: k2logas.task = "c: /windows/system/k2logas.exe"
Close Save Regedit, restart Windows
Delete C: /Windows/system/k2logas.exe
OK
51. Kuang ORIGINAL - 0.34
Clear Trojans V Original version:
Open Registry Regedit Click on:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN /
Delete the item on the right: Temp $ 1.task = "c: /windows/system/temp / full"
Clear Trojan V 0.20-0.21 version:
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN /
Delete the right item: k2ps.task = "c: /windows/system/k2ps.exe"
Clear Trojan V 0.30-0.34 version:
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN /
Delete the right of the item: K2PS_FULL.TASK = "c: /windows/system/k2ps_full.exe"
Close Save Regedit, restart Windows
Find the corresponding Trojan and delete it.
OK
52. Logger
Steps to remove Trojans:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN /
Delete the right item: ??? = "c: /windows/system/logged.exe"
Close Save Regedit, restart Windows
Delete C: / Windows / System / Logged.exe
OK
53. Magic Horse
Steps to remove Trojans:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN /
Delete the right of the item: spoolerService = "c: /windows/spoolsrv.exe"
Close Save Regedit, restart Windows
Delete C: /Windows/spoolsrv.exe
OK
54. Malicious
Steps to remove Trojans:
Open registry regedit
Click on the directory to:
HKEY_USERS / .DEFAULT / SOFTWARE / Microsoft / Windows / CurrentVersion / Policies /
Delete five items on the right: DisableregistryTools Norun NOFIND NODESK NOCLOSE
Close Save Regedit, restart Windows
OK
55. Masters Paradise
Steps to remove Trojans:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN /
Delete the right on the right: sysedit = c: / windows / sysedit.exe
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RunServices
Delete the right item: Explorer = C: /..../ Agent.exe
Close Save Regedit, restart Windows
Find Trojans and remove them. Note: c: / windows / system / below the SYSEDIT.EXE file is not 19kb, if not explained to be infected with Trojans, delete it.
56. Matrix V1.0 - 2.0
Steps to remove Trojans:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN /
Delete the right item: ??? = "c: /windows/wincfg.exe"
Close Save Regedit, restart Windows
Delete C: /Windows/wincfg.exe
OK
57. MBK
Steps to remove Trojans:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN /
Find and delete the item on the right: Explorer = "" is "Mbt.exe"
Close Save Regedit, restart Windows
Find mbt.exe and delete
OK
58. Millenium v1.0 - 2.0
Steps to remove Trojans:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN /
Delete the right item: Millenium = "c: /windows/system/reg66.exe"
Close Save Regedit, restart Windows
Delete C: /Windows/system/reg66.exe
OK
59. Mine
Steps to remove Trojans:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN /
Delete the right on the right: Windows = 'c: / msdos98.exe'
Close Save Regedit, restart Windows
Delete C: /MSDoS98.exe
Open Win.ini file
Find Run = C: /Windows/uninstallms.exe
Change to: run =
Turn off Win.ini and restart Windows
Del c: /msdos98.exe
Del c: /windows/uninst ~1.exe
Del c: /windows/system/mine.exe
OK
60. MOSUCKER
Steps to remove Trojans:
Open system.ini file
Find shell = Explorer.exe unin0686.exe
Change to: shell = Explorer.exe
Turn off System.ini and restart Windows
Delete C: /Windows/unin0686.exe
OK
61. Naebi V2.12 - 2.40
Steps to remove Trojans:
Open registry regedit
Click on the directory to:
HKEY_CURRENT_USER / SOFTWARE / MIRABILIS / ICQ / Agent / Apps / ICQ
V2.12 Delete the right of the right: Path = "C: /Windows/msramgr.exe"
V2.15 Remove the right item: Path = "c: / windows / msdll32.exe" V2.19 Delete the right of the right: Path = "C: / Windows / Naebi219.exe"
V2.xx Delete the right item: path = "c: / windows / naebi219.exe" file name may still be Naebi.exe, NS220.exe, NS227, NS231, NS234
Turn off regedit
V2.34 is the same, but it increases in Win.ini
Open Win.ini file
Remove the path behind Run =
Turn off Win.ini and restart Windows
Find the corresponding Trojan and delete
OK
62. NetController v1.08
Steps to remove Trojans:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN /
Delete the item on the right: system = 'c: /windows/system.exe'
Close Save Regedit, restart Windows
Delete C: /Windows/system.exe
OK
63. Netraider V0.0
Steps to remove Trojans:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN /
Delete the right item: rsrcnrs = 'c: /windows/rsrcnrs.exe'
Close Save Regedit, restart Windows
Delete C: /Windows/rsrcnrs.exe
OK
64. NetSphere v1.0 - 1.31337
Clear Trojans v1.0-1.30:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN /
Delete the right item: nssx = "c: /windows/system/nssx.exe"
HKEY_CURRENT_USER / SOFTWARE / Microsoft / Windows / CurrentVersion / Run
HKEY_USERS / **** / SOFTWARE / Microsoft / Windows / CurrentVersion / Run
Delete items are the same.
Close Save Regedit, restart Windows
Delete C: /Windows/system/nssx.exe
OK
Clear Trojans V1.30-1.31337:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN /
Delete the right item: execpowerprofile = "c: /windows/system/Epp32.exe"
Close Save Regedit, restart Windows
Delete C: /Windows/system/Epp32.exe
OK
65. Netspy v1.0 - 2.0
Clear Trojan V1.0:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN / Delete Items: sysprotect = "c: /windows/system/system.exe"
Close Save Regedit, restart Windows
Delete C: /Windows/system/system.exe
OK
Clear Trojans V2.0:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN /
Delete the right item: Netspy = "Netspy.exe"
Close Save Regedit, restart Windows
Find Netspy.exe and delete
OK
66. Nettrojan v1.0
Steps to remove Trojans:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN /
Delete the item on the right: *** = "c: /windows/system/glide16.exe"
Turn off regedit
Open Win.ini file
Find Run = C: /Windows/fxp.exe
Remove the path behind Run =
Turn off Win.ini and restart Windows
Find the corresponding Trojan and delete
OK
67. Nirvana / VisualKiller V1.94 - 1.95
Steps to remove Trojans:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN /
Delete the right item: theDoor = 'c: /windows/fonts/ariel.exe'
Close Save Regedit, restart Windows
Delete C: /Windows/FONTS/Ariel.exe
OK
68. Phaze Zero V1.0B 1.1
Steps to remove Trojans:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN /
Delete the right item: msgServ = "msgsvr32.exe"
Close Save Regedit, restart Windows
Find the corresponding Trojan and delete
OK
69. Prayer V1.2 - 1.5
Steps to remove Trojans:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN /
Delete the right item: sysfiles = "c: /windows/system/dlls32.exe"
HKEY_CURRENT_USER / SOFTWARE / Microsoft / Windows / CurrentVersion / Run /
Delete the right item: sysfiles = "c: /windows/system/dlls32.exe"
Close Save Regedit, restart Windows
Delete C: /Windows/system/dlls32.exeok
70. Priority (Beta)
Steps to remove Trojans:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / Run Services
/
Delete the right item: "PServer" = C: /Windows/system/pserver.exe
Close Save Regedit, restart Windows
Delete C: /Windows/system/pserver.exe
OK
71. Progenic Password Thief / Keylogger V1.0
Steps to remove Trojans:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN /
Delete the right item: PWT = "c: /windows/system/pwt.exe"
Close Save Regedit, restart Windows
Delete C: /Windows/system/PWT.exe
OK
72. Progenic v1.0 -3.0
Steps to remove Trojans:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN /
Delete the right item: scandisk = "c: /windows/scandiskvr.exe"
Close Save Regedit, restart Windows
Delete C: /Windows/ScandiskVr.exe
OK
73. Prosiak Beta - 0.70 B5
Steps to remove Trojans:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RunServices /
Delete the right of the item: Microsoft DLL Loader = "Windll32.exe"
Close Save Regedit, restart Windows
Delete C: / Windows / Windll32.exe
OK
74. Retrieve V1.3
Steps to remove Trojans:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN /
Delete the right item: Microsoft Access = "C: /Windows/access.exe"
Close Save Regedit, restart Windows
Delete C: /Windows/access.exe
OK
75. Revenger v1.0 - 1.5
Steps to remove Trojans:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN /
Delete the right item: AppName = "c: /.../ Server.exe"
Close Save Regedit, restart Windows
Find the corresponding Trojan Server.exe in C: / Windows and remove OK
76. RIPPER
Steps to remove Trojans:
Open system.ini file
Will Shell = Explorer.exe SysRunt.exe
Change to shell = Explorer.exe
Turn off System.ini and restart Windows
Find the corresponding Trojan sysrunt.exe in C: / Windows, and delete
OK
77. Satans Back Door V1.0
Steps to remove Trojans:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RunServices /
Delete the right of the right: sysprot protection = "c: /windows/sysprot.exe"
Close Save Regedit, restart Windows
Delete C: /Windows/sysprot.exe
OK
78. Schwindler V1.82
Steps to remove Trojans:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN /
Delete the right item: user.exe = "c: /windows/user.exe"
Close Save Regedit, restart Windows
Delete C: /Windows/user.exe
OK
79. Setup Trojan (SSHARE) MOD SMALL Share
This sharing hidden Trojan
Steps to remove Trojans:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / Network / Lanman /
Select the item with 'c $' on the right, and all delete
Close Save Regedit, restart Windows
OK
80. ShadowPhere V2.12.38 - 2.X
Steps to remove Trojans:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN /
Delete the right item: Winzipp = "c: /windows/system/winzipp.exe / nomsg"
Or winzip = "c: /windows/system/winzip.exe / nomsg"
Close Save Regedit, restart Windows
Delete C: / Windows / Winzipp.exe or C: / Windows / Winzip.exe
OK
81. Share All
Steps to remove Trojans:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / Network / Lanman /
Here you will see all your hard drives shared by Trojans, and remove them one by one.
82. ShitHeap
Steps to remove Trojans:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RunServices / Delete Items: Recycle-Bin = "C: /Windows/system/recycle-bin.exe"
Or Recycle-bin = "c: /windows/system.exe"
Close Save Regedit, restart Windows
Delete C: /Windows/system/recycle-bin.exe or C: /Windows/system.exe
OK
83. SNID V1 - 2
Steps to remove Trojans:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN /
Delete the right item: system-tray = 'c: /Windows/temp / 01.exe'
Close Save Regedit, restart Windows
Delete C: /Windows/temp / 01.exe
OK
84. SoftWarst
Steps to remove Trojans:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN /
Delete the right item: NetApp = C: /Windows/system/winserv.exe
Close Save Regedit, restart Windows
Delete C: /Windows/system/winserv.exe
OK
85. Spirit 2000 Beta - V1.2 (FIXED)
Clear Trojans v Beta version:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN /
Delete the item on the right: Internet = "c: /windows/netip.exe"
Turn off regedit
Open Win.ini file
Find Run = C: /Windows/netip.exe
Change to: run =
Turn off Win.ini and restart Windows
Delete C: /Windows/netip.exe and C: /Windows/netip.exe
OK
Clear Trojan V 1.2 version:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN /
Delete the right one of the items: systemtray = "c: /windows/windown.exe"
Close Save Regedit, restart Windows
Delete C: /Windows/Windown.exe
OK
Clear Trojans V 1.2 (Fixed) version:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN /
Delete the right item: server 1.2.exe = "c: / windows / server 1.2.exe"
Close Save Regedit, restart Windows
Delete C: / Windows / Server 1.2.exe
Ok86. Stealth V2.0 - 2.16
Steps to remove Trojans:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN /
Delete the right item: WinProtect System = "C: /Windows/WinProtecte.exe
Close Save Regedit, restart Windows
Delete C: /Windows/WinProtecte.exe
OK
87. Subseven - Introduction
Clear Trojans V1.0 - 1.1:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN /
Delete the right of the item: SystemTrayicon = "C: /Windows/systrayicon.exe"
Close Save Regedit, restart Windows
Delete C: /Windows/SYSTRAYICON.EXE
OK
Clear Trojans V1.3 - 1.4 - 1.5:
Open Win.ini file
Find Run = NODLL
Change to Run =
Turn off Win.ini and restart Windows
Delete C: /Windows/NODLL.EXE
OK
Clear Trojans V1.6:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN /
Delete the right item: systemtray = "SYSTRAY.EXE"
Close Save Regedit, restart Windows
Delete C: /Windows/SYSTRAY.EXE
OK
Clear Trojans V1.7:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RunServices
/
Find the item on the right: c: /windows/kernel16.dl, and delete
Close Save Regedit, restart Windows
Delete C: /Windows/kernel16.dl
OK
Clear Trojans V1.8:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN and
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RunServices
/
Find the item on the right: c: /windows/system.ini., And delete
Close the saved regedit.
Open Win.ini file
Find Run = kernel16.dl
Change to Run =
Turn off Win.ini.
Open system.ini file
Find Shell = Explorer.exe kernel32.dl
Change to shell = Explorer.exe
Turn off System.ini and restart Windows
Delete C: /Windows/kernel16.dl
OK
Clear Trojans V1.9 - 1.9B: Open Registry Regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN and
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RunServices
/
Delete the right of the item: registryScan = "rundll16.exe"
Close Save Regedit, restart Windows
Delete C: /Windows/rundll16.exe
OK
Clear Trojans V2.0:
Open system.ini file
Find shell = Explorer.exe TrojanName.exe
Change to shell = Explorer.exe
Turn off System.ini and restart Windows
Delete C: /Windows/rundll16.exe
OK
Clear Trojans v2.1 - 2.1 Gold Substealth- 2.1.3 Mod 2.1.3 MUIE 2.1 Bonus:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN and
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RunServices
/
Delete the right item: WinLoader = msrexe.exe
HKEY_CLASS_ROOT / EXEFILE / Shell / Open / Command
Change the item on the right to: @ = "/"% 1 / "% *"
Close the saved regedit.
Open Win.ini file
Find Run = MSREXE.EXE and
Load = msrexe.exe
Change to Run =
LOAD =
Turn off Win.ini.
Open system.ini file
Find Shell = Explore.exe Msrexe.exe
Change to shell = Explorer.exe
Turn off System.ini and restart Windows
Delete C: / Windows / MSREXE.EXE
C: /Windows/system/systray.dll
OK
Clear Trojans V2.2B1:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN and
Delete the right item: loader = "c: / windows / system / ***"
Note: The loader and file name are randomly changed.
Close the saved regedit.
Open Win.ini file
Change to Run =
Turn off Win.ini.
Open system.ini file
Change to shell = Explorer.exe
Turn off System.ini and restart Windows
Delete the corresponding Trojan
OK
88. Telecommando 1.54
Steps to remove Trojans:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN /
Delete the right item: systemApp = "odbc.exe" Close Save regedit, restart Windows
Delete C: / Windows / System / ODBC.EXE
OK
89. THE UNEXPLAINED
Steps to remove Trojans:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN /
Delete the item on the right: inetb00st = "c: /windows/tempinetb00st.exe"
Close Save Regedit, restart Windows
Delete C: /Windows/TempineTB00st.exe
OK
90. Thing V1.00 - 1.60
Clear Trojans V1.00-1.12:
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN /
Delete the right item: (default) = "c: /some/path/here/thing.exe"
There are also some:
HKEY_LOCAL_MACHINE / SYSTEM / CURRENTCONTROLSET / CONTROL / SessionManager / KNown16DLLS /
Delete the right item: wsasrv.exe = "wsasrv.exe"
Close Save Regedit, restart Windows
Delete c: /some/path/here/thing.exe
OK
Clear Trojan V 1.20 version:
Enter MS_DOS mode:
Del Winspc13.exe
Del ms097.exe
Open system.ini file
Find shell = Explorer.exe ms097.exe
Change to: shell = Explorer.exe
Turn off System.ini and restart Windows
OK
Clear Trojan V1.50:
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN /
The path and file name of this project is randomly changed, and the suspicious file path is checked, and it is deleted.
Close the saved regedit.
Open system.ini file
Find shell = Explorer.exe is a Trojan file
Change to: shell = Explorer.exe
Turn off System.ini and restart Windows
Delete the corresponding Trojan file
OK
Clear Trojan V1.50:
Enter MS_DOS mode:
Del Winspc13.exe
Del ms097.exe
Open system.ini file
Find shell = Explorer.exe is a Trojan file
Change to: shell = Explorer.exe
Turn off System.ini and restart Windows
Delete the corresponding Trojan file
OK
91. Transmission Scount V1.1 - 1.2
Steps to remove Trojans:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN /
Delete the right item: kernel16 "= C: /Windows/kernel16.exe Turn off the regedit, restart Windows
Delete C: /Windows/kernel16.exe
OK
92. Trinoo
Steps to remove Trojans:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN /
Delete the right of the right: System Services = Service.exe
Close Save Regedit, restart Windows
Delete C: /Windows/system/service.exe
OK
93. Trojan COW V1.0
Steps to remove Trojans:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN /
Delete the right item: syswindow = "c: /windows/syswindow.exe"
Close Save Regedit, restart Windows
Delete C: /Windows/sysWindow.exe
OK
94. Tryit
Steps to remove Trojans:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN /
Delete the right item: RC5DEC = C: / Program Files / Internet Explorer / _. EXE -GUISTART
Close Save Regedit, restart Windows
Delete C: / Program Files / Internet Explorer /_. EXE
OK
95. Vampire V1.0 - 1.2
Steps to remove Trojans:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN /
Delete the item on the right: sockets = "c: /windows/system/sockets.exe"
Close Save Regedit, restart Windows
Delete C: /Windows/system/sockets.exe
OK
96. WARTROJAN V1.0 - 2.0
Steps to remove Trojans:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN /
Delete the right item: kernel32 = "c: /somepath/server.exe"
Close Save Regedit, restart Windows
Delete c: /somepath/server.exe
OK
97. WCRAT V1.2B
Steps to remove Trojans:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN /
Delete the right item: MS Windows System Explorer = "C: /Windows/SYSEXPLOR.exe"
Close Save Regedit, restart Windows
Delete C: /Windows/sysexplor.exe
OK
98. WebEx (V1.2, 1.3, And 1.4)
Steps to remove Trojans:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN /
Delete the right item: rundl32 = "c: / windows / system / task_bar"
Close Save Regedit, restart Windows
Delete C: /Windows/system/task_bar.exe and c: /windows/system/msinet.ocx
OK
99. WinCrash V2
Steps to remove Trojans:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN /
Delete the right item: WinManager = "c: /windows/server.exe"
Turn off regedit
Open Win.ini file
Find Run = C: /Windows/Server.exe
Change to: run =
Save Win.ini, restart Windows
Delete C: /Windows/Server.exe
OK
100. WinCrash
Steps to remove Trojans:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN /
Delete the right item: msmanager = "server.exe"
Close Save Regedit, restart Windows
Delete C: / Windows / System / Server.exe
OK
101. xanadu v1.1
Steps to remove Trojans:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN /
Delete the right item: setup = "c: /somepath/setup.exe"
Close Save Regedit, restart Windows
Delete C: /SOMEPath/setup.exe
OK
102. xplorer v1.20
Steps to remove Trojans:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN /
Delete the right item: PCX = "c: /windows/system/pcx.exe"
Close Save Regedit, restart Windows
Delete C: /Windows/system/pcx.exe
OK
103. XTCP V2.0 - 2.1
Steps to remove Trojans:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RUN /
Delete the right item: msgsv32 = "c: /windows/system/winmsg32.exe" Close Save Regedit, restart Windows
Delete C: /Windows/system/winmsg32.exe
OK
104. YAT
Steps to remove Trojans:
Open registry regedit
Click on the directory to:
HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / RunServices /
Delete the item on the right: Batterieanzeige = 'c: /pathnamehere/server.exe / nomsg'
Close Save Regedit, restart Windows
Delete c: /pathnamehere/server.exe