Share
Follow the steps to fix the issue
1. Click Start > Run.
2. Type regedit
3. Click OK.
4. Navigate to and delete the following entries:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\"IEXPLORER"="%System%\iexplorer.exe"
5. Navigate to and delte the following registry subkeys:
* HKEY_CURRENT_USER\Software\mmtest
* HKEY_CURRENT_USER\Software\mmtest\IEXPLORER
6. Restore the following registry entries to their original values, if required:
* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\advanced\folder\hidden\showall\"CheckedValue" = "0"
* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\[FILE NAME]\"Debugger" = "%System%\wuauc1t.exe"
[FILE NAME] represents any application executable file on the compromised computer, including, but not limited to the following strings:
* 360rpt.exe
* 360safe.exe
* 360tray.exe
* ANTIARP.exe
* Ast.exe
* AutoRunKiller.exe
* AvMonitor.exe
* AVP.exe
* CCenter.exe
* Frameworkservice.exe
* IceSword.exe
* Iparmor.exe
* KASARP.exe
* KRegEx.exe
* KVMonxp.kxp
* KVSrvXP.exe
* KVWSC.exe
* Mmsk.exe
* Navapsvc.exe
* Nod32kui.exe
* QQDOCTOR.exe
* Regedit.exe
* VPC32.exe
* VPTRAY.exe
* WOPTILITIES.exe
* Wuauclt.exe
7. Exit the Registry Editor.
Follow the steps to fix the issue
1. Click Start > Run.
2. Type regedit
3. Click OK.
4. Navigate to and delete the following entries:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\"IEXPLORER"="%System%\iexplorer.exe"
5. Navigate to and delte the following registry subkeys:
* HKEY_CURRENT_USER\Software\mmtest
* HKEY_CURRENT_USER\Software\mmtest\IEXPLORER
6. Restore the following registry entries to their original values, if required:
* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\advanced\folder\hidden\showall\"CheckedValue" = "0"
* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\[FILE NAME]\"Debugger" = "%System%\wuauc1t.exe"
[FILE NAME] represents any application executable file on the compromised computer, including, but not limited to the following strings:
* 360rpt.exe
* 360safe.exe
* 360tray.exe
* ANTIARP.exe
* Ast.exe
* AutoRunKiller.exe
* AvMonitor.exe
* AVP.exe
* CCenter.exe
* Frameworkservice.exe
* IceSword.exe
* Iparmor.exe
* KASARP.exe
* KRegEx.exe
* KVMonxp.kxp
* KVSrvXP.exe
* KVWSC.exe
* Mmsk.exe
* Navapsvc.exe
* Nod32kui.exe
* QQDOCTOR.exe
* Regedit.exe
* VPC32.exe
* VPTRAY.exe
* WOPTILITIES.exe
* Wuauclt.exe
7. Exit the Registry Editor.
Related post :-
0 comments:
Post a Comment