CleanThis provide fake features such as Quick Scan, Full Scan and Firewall. It scares the user that the %ProgramFiles%\Messenger\msmsgs.exe is infected with Trojan.Horse.Win32.PAV.64.a. Don't be cheated as the file is clean. It disable Windows Task Manager and stop other legitimate antivirus program from protecting the computer.
CleanThis should be removed immediately!
CleanThis Removal Guide
Kill Process
(How to kill a process effectively?)
gog.exe
Delete Registry
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon "Shell" = "%Documents and Settings%\[UserName]\Application Data\gog.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "CleanThis"
Remove Folders and Files
%Documents and Settings%\[User Name]\Desktop\CleanThis.lnk
%Documents and Settings%\[User Name]\Start Menu\Programs\CleanThis.lnk
%Documents and Settings%\[User Name]\Application Data\[random].bat
%Documents and Settings%\[User Name]\Application Data\gog.exe
%Windows%\Tasks\At[random].job
CleanThis should be removed immediately!
CleanThis Removal Guide
Kill Process
(How to kill a process effectively?)
gog.exe
Delete Registry
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon "Shell" = "%Documents and Settings%\[UserName]\Application Data\gog.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "CleanThis"
Remove Folders and Files
%Documents and Settings%\[User Name]\Desktop\CleanThis.lnk
%Documents and Settings%\[User Name]\Start Menu\Programs\CleanThis.lnk
%Documents and Settings%\[User Name]\Application Data\[random].bat
%Documents and Settings%\[User Name]\Application Data\gog.exe
%Windows%\Tasks\At[random].job
No comments:
Post a Comment