You are on page 1of 4

PROBLEM – having torjan infection- blastnnn.

exe 300kb
Scvvhost .exe300kb
SLOW COMPUTER, some program not run

TRY THESE

1. check the memory of the computer.


2. implement disk clean up.
3. check services which is stopped.
4. check tasks which are running in the computer
5. implement disk defragmenter.
6. check file\ folder which is formed at the time of computer
start running slow and remove this.
7. increase swap file size from the start-setting-system –
advance-performance.
8. reduce start up programs
9. delete all log files from the computer

second times infestion-torjans services.exe 37 kb


- change in file extension
- make main file hidden or attributed
to be done –
1. change remote registry disable from automatic.
2. use win cmd program to change the attribute.
3. identify the virus running process
4. stop the virus process running by process viewer , spybot
snd and any other program
5. remove virus file then check
task manager disabled by administer
1. remove virus file
2. REG add
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies
\System /v DisableTaskMgr /t REG_DWORD
3. paste it on the run and opt- yes
4. REG add HKCU\Software\Microsoft\Windows\CurrentVersion\Pol icies\System
/v DisableRegistryTools /t REG_DWORD /d 0 /f
5. REG add
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies
\System /v DisableRegistryTools

Method 1 ­ Using the Group Policy Editor in Windows XP Professional

1. Click Start, Run, type gpedit.msc and click OK.
2. Under User Configuration, Click on the plus (+) next to Administrative Templates
3. Click on the plus (+) next tSystem, then click on Ctrl+Alt+Delete Options
4. Find Remove Task Manager in the right­hand pane and double click on it
5. Choose the option "Not Configured"  and click Ok. 
6. Close the Group Policy Window

Method 2:  Change the Task Manager Option through the Run line

1. Click on Start, Run and type the following command exactly and press Enter 

REG add HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v 
DisableTaskMgr /t REG_DWORD /d 0 /f

Method 3: Change Task Manager through a Registry REG file

1. Click on Start, Run, and type Notepad and press Enter 
2. Copy and paste the information between the dotted lines into Notepad and save it to your 
desktop as taskmanager.reg 

­­­­­­­­­­­­­­­­­­­­­­­­­­­­­­­­­­­­
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=dword:00000000
­­­­­­­­­­­­­­­­­­­­­­­­­­­­­­­­­­­­­

      3. Double click on the taskmanager.reg file to enter the information into the Windows registry
Method 4: Delete the restriction in the registry manually

1. Click on Start, Run, and type REGEDIT and press Enter 
2. Navigate to the following branch

HKEY_CURRENT_USER \ Software \ Microsoft \ Windows \ CurrentVersion \ Policies\ 
System

3. In the right pane, find and delete the value named DisableTaskMgr
4. Close the registry editor

Method 5: Download and Run FixTaskManager program 

1. Click on the following links and download the program FixTaskManager to your Desktop

Main Site

Backup Location

2. Double­click on the file FixTaskManager on your desktop and run it

Abebot Trojan manual removal instructions:

Remove Abebot files:

config.xml
1205156013.log
Sites.bl
%UserProfile%\Local Settings\Temp\[RANDOM CHARACTERS].tmp
%UserProfile%\Start Menu\Programs\Startup\.protected
PC-Antispyware Uninstall.lnk
PC-Antispyware.lnk
PC-Antispyware.db
pcantispyware.pkg
program.info

Delete Abebot registry entries:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\”PC-Antispyware” =
“”C:\Program Files\PC-Antispyware\PC-Antispyware.exe” hide”
HKEY_CURRENT_USER\Software\PC-Antispyware
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PC-Antispyware
HKEY_LOCAL_MACHINE\SOFTWARE\PC-Antispyware
HKEY_CLASSES_ROOT\CLSID\{10F0C2A9-8E38-43e3-204D-45524C494E20}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{10F0C2A9-8E38-43e3-204D-45524C494E20}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
{10F0C2A9-8E38-43e3-204D-45524C494E20}

Check bill by this address


http://www.mathuratelecom.com/ebill/INDEX.HTM

You might also like