1. Ice v1.1 v2.2 ,
nike air force one
made ice is the best Trojan horse v1.1
Clear Regedit
clicked open the registry to:
HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run
find the following two paths, and delete
\* plr.exe \br> restart. OK
remove trojan v2.2
server program,
Air Force 1 Classic Low, the path the user is free to define, write to the registry key name you can own definition.
, therefore, can not be clearly stated.
You can view the registry,
air force 1, delete the suspicious file path.
restart to MSDOS mode
delete the Trojan registry
corresponding to restart Windows.
OK
2. Acid Battery v1.0
steps to remove trojan:
open the registry Regedit
click on the directory to:
HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run
delete the right of the Explorer = \> Note: Do not remove the right ExpLorer.exe procedures, among them only the difference between i and L.
restart.
OK
3. Acid Shiver v1.0 + 1.0Mod + lmacid
steps to remove trojan:
restart to MSDOS mode
deleted C: \ windows \ MSGSVR16.EXE
then return to Windows Open the Registry Regedit
system
click the directory to:
HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run
remove the right of the Explorer = \> HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ RunService *
remove the right of ** plorer = \OK
restart to MSDOS mode
deleted C: \ windows \ wintour.exe and then back to open the Windows system registry Regedit
click the directory to:
HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run
remove the right of the Wintour = \WINDOWS \ WINTOUR.EXE \
4. Ambush
steps to remove trojan:
open the registry Regedit
click on the directory to:
HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run \
remove the right of the zka = \
OK
5. AOL Trojan
steps to remove trojan:
way to boot into MSDOS
deleted C: \ command.exe (file deleted before the abolition of the implicit attributes)
Note: Do not delete the true The command.com file.
deleted C: \ americ ~ 1.0 \ buddyl ~ 1.exe (delete the file before the abolition of hidden attributes)
deleted C: \ windows \ system \ norton ~ 1 \ regist ~ 1.exe (deleted before the cancel hidden file attributes)
open the WIN.INI file
in the [WINDOWS] the following \br> run =
load =
save the WIN.INI
but also to correct the registry Regedit
click on the directory to:
HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run
delete right WinProfile = c: \ command.exe
close Regedit, restart Windows.
6. Asylum v0.1, 0.1.1,
air force ones, 0.1.2, 0.1.3 + Mini 1.0, 1.1
steps to remove trojan:
Note: The default file name is Trojan wincmp32.exe, however, programs are free to change the file name.
we can modify the system.ini and win.ini Trojans two files to remove the Trojan. Open the system.ini file
in [BOOT] Here are a \The correct file name is explorer.exe
if not \
open the win.ini system.ini
save out the file
in the [WINDOWS] run =
below a = if you see the path behind the file name,
nike air force one low, you must delete it.
right should be run = nothing behind.
= file name is the path behind the horse and put it to find out, delete it.
save out of win.ini.
OK
7. AttackFTP
steps to remove trojan:
open the win.ini file
in the [WINDOWS] load = wscan.exe
below to delete wscan.exe, the right is the load =
Save and exit win.ini. Click to open the registry Regedit
directory to:
HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run
remove the right of the Reminder = \reboot into MSDOS system
deleted C: \ windows \ system \ wscan.exe
8. Back Construction 1.0 - 2.5
steps to remove trojan:
open the registry Regedit
click on the directory to:
HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run
delete the right of the \
9. BackDoor v2.00 - v2.03
steps to remove trojan:
open the registry Regedit
click on the directory to:
HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run
Remove the right side of the 'c: \ windows \ notpa.exe / o = yes'
close Regedit,
air force one 25th, reboot into MSDOS system
delete c: \ windows \ notpa.exe
Note: Do not delete real laptop program
notepad.exe
10. BF Evolution v5.3.12
steps to remove trojan:
open the registry Regedit
click on the directory to:
HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run
delete the right (Default) = \
the C: \ windows \ system \. exe (space exe file)