[Trojaner]WinToolsA.exe entfernen

<LORD>

Lt. Commander
Registriert
Juni 2004
Beiträge
1.393
Mein Vadda hat inner Arbeit nen WinNT Rechner. Der hat scheinbar nen Trojaner drauf der WinToolsA.exe in der prozessüberischt heißt. Die IT'ler aus der Arbeit haben den ned runterbekommen.

Ich wollt fragen ob ihr den kennt, am besten noch wie man ihn eben wieder runterbekommt.
 
Manual removal
Please follow the instructions below if you would like to remove Win-Tools manually. Please notice that you must follow the instructions very carefully and delete everything that is mentioned. In most cases the removal will fail if one single item is not deleted. If Win-Tools remains on your system after stepping through the removal instructions, please double-check by stepping through them again.
Start your computer in safe mode.
Start the registry editor. This is done by clicking Start then Run. (The Run dialog will appear.) Type regedit and click OK. (The registry editor will open.)
Browse to the key:
'HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run'
In the right pane, delete the value called 'WinTools', if it exists.
Browse to the key:
'HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ RunOnce'
In the right pane, delete the value called 'WinTools', if it exists.
Browse to the key:
'HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ RunServices'
In the right pane, delete the value called 'WinTools', if it exists.
Browse to the key:
'HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ RunServicesOnce'
In the right pane, delete the value called 'WinTools', if it exists.
Delete 'HKEY_LOCAL_MACHINE\SOFTWARE \ Classes \ CLSID \ {87766247-311C-43B4-8499-3D5FEC94A183}', if it exists.
Delete 'HKEY_LOCAL_MACHINE\SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Explorer\Browser Helper Objects \ {87766247-311C-43B4-8499-3D5FEC94A183}', if it exists.
Delete 'HKEY_LOCAL_MACHINE\SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Uninstall \ WinTools', if it exists.
Exit the registry editor.
Start Windows Explorer and delete:
%ProgramsDir%\Common files\WinTools\WToolsA.exe
%ProgramsDir%\Common files\WinTools\WSup.exe
%ProgramsDir%\Common files\WinTools\WToolsS.exe
%ProgramsDir%\Common files\WinTools\WToolsB.dll
Note: %ProgramsDir% is a variable (?). By default, this is C:\Program Files.
Hoffe das hilft. ;)
 
So mein Vater wird das am Montag mal auprobieren. Er ha aber gleich gmeint das WIN NT keinen Safe Mode hat. kann das sein?

Könnte probleme geben von wegen Dateien löschen usw.
 
Zurück
Oben