Windows verifies the activation Trojan and proposes a solution

  

Microsoft has confirmed the Windows product activation Trojan (Trojan.Kardphisher) reported by Symantec. The malicious code itself is not a big threat, just posing as a genuine verification tool for Windows, but it is dangerous to recruit the credit card information.

Symantec provides the method to clear Trojan.Kardphisher:

1. Restart the infected machine, select only NO

2. Press F8 to enter safe mode when restarting

3. Start -> Run

4. Enter regedit

5. Locate and delete the following key values:

HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows/CurrentVersion/Runsoft2 vOQ>&wb+Ax

HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows/CurrentVersion/Policies/System/DisableTaskMgr , Rd_Auga

6. Launch Registry Editor

Of course, you can also give the Trojan a false account information to fool it, so enter the system and find the key to delete:

HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows/CurrentVersion/Runsoft2

Copyright © Windows knowledge All Rights Reserved