2008年10月13日 星期一

Delete "taskmgr" warning

1. Click Start > Run.
2. Type regedit
3. Click OK.
Note: If the registry editor fails to open the threat may have modified the registry to prevent access to the registry editor. Security Response has developed a tool to resolve this problem. Download and run this tool, and then continue with the removal.
4. Navigate to the subkey:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{A5CDF7EC-751B-46aa-AD69-4005FE080DE8}
5. In the right pane, delete the value:
"stubpath" = "[PATH TO TROJAN]\pligde.exe"
6. Navigate to the subkey:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{0002BB0C-D318-FD27-0505-050505040105}
7. In the right pane, delete the value:
"StubPath" = "[PATH TO TROJAN]\wmedia.exe"
8. Navigate to the subkey:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{9B71D88C-C598-4935-C5D1-43AA4DB90836}
9. In the right pane, delete the value:
"stubpath" = "[PATH TO TROJAN]\explorer..exe s"
10. Navigate to the subkey:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
11. In the right pane, delete the value:
"StartKey" = "[PATH TO TROJAN]\pligde.exe""MSN Messenger" = "[PATH TO TROJAN]\explorer..exe"
12. Navigate to and delete the subkeys:
HKEY_CURRENT_USER\SOFTWARE\SKav
HKEY_CURRENT_USER\Software\Wget
HKEY_LOCAL_MACHINE\SOFTWARE\SKav
HKEY_LOCAL_MACHINE\SOFTWARE\Wget
13. Exit the Registry Editor.

沒有留言: