Comments
SubSeven 2.2 beta 2 now
can actually infect Windows NT like version 2.2 was supose to. Other then
that nothing new here at all from the previous beta 1.
How To Remove
Quick fix: no quick
fix programs
Manual removal:
-
Remove the Loader
key in the registry located at either HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
or HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices.
Which can be done with regedit or any other registry editing program.
-
Open the system.ini(Usually
c:\windows\system.ini) and remove the key: shell=Explorer.exe
c:\windows\sytem\some random name.exe under [boot], to shell=explorer.exe.
This can be done with any text editing program.
-
Open the win.ini(Usually
c:\windows\win.ini) and remove the key: load=c:\windows\system\some
random name.exeunder [Windows], this can be done with any text editing
program.
-
Reboot the computer or
close the trojan.
-
Delete the trojan file
in the windows system directory.
|