2. Don't forget to back up your system before making any changes for future restore job when necessary.
3. Remove these Win32.Mebroot.U files:
- %UserProfile%\Application Data\PAV
- %UserProfile%\Local Settings\Temp\kjkkklklj.bat
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce 'SelfdelNT'
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon 'Shell'='%UserProfile%\Application Data\antispy.exe'
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce
- HKEY_CLASSES_ROOT\Folder\shellex\ContextMenuHandlers\SimpleShlExt
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run '[random string]'
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings 'ProxyServer' = 'http=127.0.0.1:5555'
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings 'ProxyOverride' = ' '
5. It is possibly for Win32.Mebroot.U to load by hiding within the system WIN.INI file and the strings "run=" and "load=". So you must check carefully in order to thoroughly remove it from your computer.
6. It is necessary for you to clean the IE temporary files where the original carrier may store.
Or you can download malware removal here:
Win32/Mebroot removal
Or you can download malware removal here:
Win32/Mebroot removal
No comments:
Post a Comment