1. Boot your computer into safe mode to close all running processes.
2. Remember to back up your system before making any changes for future restore job when necessary.
3. Remove these Win32.Ramnit-G files:
%UserProfile%\Local Settings\Temp\kjkkklklj.bat
%Documents and Settings%\[UserName]\Desktop\Protection Center Support.lnk
4. Open Registry Editor to delete the following registry entries:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run 'tmp'
HKEY_LOCAL_MACHINE\SOFTWARE\Paladin Antivirus
HKEY_CLASSES_ROOT\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}
HKEY_CURRENT_USER\Software\Paladin Antivirus
HKEY_CURRENT_USER\Software\Paladin Antivirus
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run '[random string]'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations 'LowRiskFileTypes' = '.exe'
5. It is possibly for Win32.Ramnit-G to load by hiding within the system WIN.INI file and the strings "run=" and "load=". So you must check carefully in order to thoroughly remove it from your computer.
6 It is necessary for you t clean the IE temporary files where the original carrier may store.
2. Remember to back up your system before making any changes for future restore job when necessary.
3. Remove these Win32.Ramnit-G files:
%UserProfile%\Local Settings\Temp\kjkkklklj.bat
%Documents and Settings%\[UserName]\Desktop\Protection Center Support.lnk
4. Open Registry Editor to delete the following registry entries:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run 'tmp'
HKEY_LOCAL_MACHINE\SOFTWARE\Paladin Antivirus
HKEY_CLASSES_ROOT\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}
HKEY_CURRENT_USER\Software\Paladin Antivirus
HKEY_CURRENT_USER\Software\Paladin Antivirus
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run '[random string]'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations 'LowRiskFileTypes' = '.exe'
5. It is possibly for Win32.Ramnit-G to load by hiding within the system WIN.INI file and the strings "run=" and "load=". So you must check carefully in order to thoroughly remove it from your computer.
6 It is necessary for you t clean the IE temporary files where the original carrier may store.
0 comments:
Post a Comment