Thursday, July 10, 2008

Trojan NTOS.EXE,dc.exe

These Trojans attack the start utility. Please read the blog to use Msconfig to remove them from start registry either under
HKEY_CURRENT_USER
HKEY_LOCAL_MACHINE

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run

delete them from process explorer
Download the process explorer http://download.sysinternals.com/Files/ProcessExplorer.zip Process explorerhttp://technet.microsoft.com/en-us/sysinternals/bb896653.aspx

No comments: