RE: TROJAN
Try to get windates.exe quarantained.
If this doesn't help:
1. Terminate the process (CTRL + ALT +Delete >> Processes >> windates.exe).
2. Go to Start >> Run >> regedit >> \HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
and delete any of the following values that you find, or any value that refers to the file, which is detected as the Trojan:
"Configuration Manager"="Cnfgldr.exe"
"System Monitor"="Sysmon16.exe"
"MSSQL"="Mssql.exe"
"Configuration Loader" = "aim95.exe"
"Internet Config" = "svchosts.exe"
"System33" = "%System%\FB_PNU.EXE"
"Configuration Loader"="cmd32.exe"
"Windows Explorer"="Explorer.exe"
"Configuration Loader"="IEXPL0RE.EXE"
"Configuration Loader"="%System%\iexplore.exe"
"Sock32"="sock32.exe"
"Configuration Loader"="MSTasks.exe"
"Windows Services"="service.exe"
"Registry Checker" = "%System%\Regrun.exe"
"Internet Protocol Configuration Loader" = "ipcl32.exe"
"syswin32" = "syswin32.exe"
Don't worry about programs needed by Windows to operate good. They don't appear on this list.
Close down the registry and it won't restart your computer anylonger and it won't be started when Windows boots.
|