Guide to Manually Remove Trojan.Multi.Cerstor.a
Note: Since the manual removal is a complicated task which involves the deletion of files and registry entries, we sincerely suggest that you back up the Windows registry and important data and before you start to the manual removal. Then, follow the steps to remove the Trojan horse.
1. Restart your infected computer.
2. As it starts up, you should tap the key F8 several times until the Windows Advanced Options Menu appears on the screen.
3. Highlight the “Safe Mode with Networking” option by using the arrow keys.
4. Press Enter to proceed.
5. Press keys CTRL+ALT+DEL together to open the Windows Task Manager.
6. Go to “Processes” tab, search for and stop the processes related to Trojan.Multi.Cerstor.a.
7. Locate the files listed below and delete all of them from your computer.
%AppData%\Bifrost\server.exe
%ProgramFiles%\random.exe
C:\WINDOWS\trlrokgq
C:\Documents and Settings\Administrator\Local Settings\Temp\dinotifyb.exe
C:\Documents and Settings\Administrator\Local Settings\nsg8.tmp\execpri.dll
C:\Documents and Settings\Administrator\Local Settings\Temp\nsg8.tmp\inetc.dll
8. Click on the Start menu and go to Run.
9. Type “regedit” into the dialog box and press Enter. This will open the Registry Editor.
10. In the Registry Editor, find out and remove the registry entries associated with the Trojan horse.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current Version\Run\random.exe”
HKEY_CURRENT_USER\AppEvents\Schemes\Apps\Explorer\Navigating
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations
HKEY_CURRENT_USER\Software\Microsoft\CurrentVersion\Run\”MSN” = “%Temp%\34542.exe”
12. Reboot your computer back to the normal mode to check whether the Trojan horse has been completely removed from your computer.
No comments:
Post a Comment