These Trojans attack the start utility. Please read the blog to use Msconfig to remove them from start registry either under
HKEY_CURRENT_USER
HKEY_LOCAL_MACHINE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
delete them from process explorer
Download the process explorer http://download.sysinternals.com/Files/ProcessExplorer.zip Process explorerhttp://technet.microsoft.com/en-us/sysinternals/bb896653.aspx
Thursday, July 10, 2008
Subscribe to:
Post Comments (Atom)
No comments:
Post a Comment