Comments
SubSeven 1.7 modifies the
registry to recognize .dl files as applications.
Note: This is a trojan
that can be submitted to us for analysis. We can possibly determine
for you the password that was used and the ICQ UIN, Email or IRC channel
that was being notified. For more information on submitting trojan files
to us read here.
How To Remove
Quick fix: no
quick fix programs
Manual removal:
-
Remove the KERNEL16
key in the registry located at HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices.
Which can be done with regedit or any other registry editing program
-
Reboot the computer or close
the trojan.
-
Delete the trojan files kernel16.dl
in the windows directory and watching.dll
located in the Windows System directory(Usually c:\windows\system).
|