Warning: Be sure to make a backup copy of your registry prior to making any changes to it.
- Start your computer in Safe Mode by pressing F8 once Windows first begins to load. Be sure that you login as Administrator.
- Go to Start>> Search all files and folders. Search for the viruses file name and delete it where-ever it is found.
- Go back to Start>> Run. Type in: regedit [Enter] or click OK.
- Navigate to the following Registry keys one at a time:
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg
- Click the last string entry (eg: startupreg & run) to empty its contents into the right pane. Look for entries that reference your specific Trojan file. Delete the strings that contain such reference. Be sure that you do not delete any string values in the left pane.
- Close the Registry Editor when completed. Restart your computer normally.
- Update your Antivirus software and run a full system scan. If your antivirus software states that your system is clean, you will now need to remove all of your restore points as the virus may reside there. The next time that you would use system restore, you will re-infect your system.
Here's how to remove your restore points:
- Go to Start>> Control Panel>> System>> System Restore tab. Check the box to "Turn off system restore on all drives".
- Click Apply. Then click OK. This will remove all restore points.
- Follow the instructions in #1 above to restore your system restore on all drives by unchecking the entry.
- Create a new clean restore point by going to Start>> All Programs>> Accessories>> System Tools>> System Restore.
- Click "Create a Restore Point" then click Next.
- Enter a name for this Restore Point and then click Create.
Note: If everything seems to be running well at this point, delete the backup copy of your registry. Then, empty your recycle bin.