How can you remove Download Trojan that has infected the file C WINDOWS isrvs sysupd.dll?
Detailed Explanation
1. back up your registry and your system, and/or setting a Restore Point
2. Open Task Manager:Stop these processes
desktop.exe edmond.exe ffisearch.exe
3.open registry start/run/regedit
If these keys are there delete and reboot
HKEY_LOCAL_MACHINE\software\Microsoft\windows\currentversion\run\ffis
HKEY_LOCAL_MACHINE\software\Microsoft\windows\currentversion\run\desktop search
4. Open registry again and delete any of these keys if present
HKEY_CLASSES_ROOT\clsid\{5b4ab8e2-6dc5-477a-b637-bf3c1a2e5993}
HKEY_CLASSES_ROOT\clsid\{950238fb-c706-4791-8674-4d429f85897e}
HKEY_CLASSES_ROOT\mfiltis HKEY_LOCAL_MACHINE\software\Microsoft\windows\currentversion\policies\ext\clsid\{5b4ab8e2-6dc5-477a-b637-bf3c1a2e5993}
HKEY_LOCAL_MACHINE\software\Microsoft\windows\currentversion\run\desktop search
HKEY_LOCAL_MACHINE\software\Microsoft\windows\currentversion\run\ffis
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\delprot
5.Remove these files from windows if they're present
systemroot+\isrvs\desktop.exe systemroot+\isrvs\edmond.exe systemroot+\isrvs\ffisearch.exe systemroot+\isrvs\isearch.xpi systemroot+\isrvs\mfiltis.dll systemroot+\isrvs\msdbhk.dll systemroot+\isrvs\sysupd.dll desktopdir+\virus hunter security.lnk desktopdir+\your platinum visa.lnk systemroot+\delprot.ini desktopdir+\big dick school for 2.95.URL desktopdir+\anal exploits.URL desktopdir+\evidence eraser.lnk desktopdir+\popup blocker stops popups.lnk desktopdir+\spyware avenger.lnk desktopdir+\virus hunter security.lnk desktopdir+\your platinum visa.lnk systemroot+\delprot.ini systemroot+\delprot.log delprot.sys
5. Remove directory systemroot+\isrvs
6.Reboot and it should be fine
Discussion (0)
No comments yet. Be the first to share your thoughts!
Share Your Thoughts