Spyware Removal

Remove Juny


What is Juny and removal instructions

Juny is a trojan that encrypts files of predefined types (libraries, executables, web pages, programming files, archives, text documents, office projects, etc.), so they can no longer be accessed by the user. It also drops a text file on the desktop containing the list of encrypted files. Upon execution, Juny displays a message in Russian warning the user that the system is infected with the trojan. This message asks the victim to pay for decrypting files and send the ransom to a specified e-mail address. Juny automatically runs on every Windows startup.

Juny manual removal:

Kill processes:
krnlmgr.exe
Delete registry values:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Kernel Manager
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Kernel Manager
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\Open\Command\(Default)=%System%\krnlmgr.exe %1 %*
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\EventSystem.EventSystem\PrivateData\FuckedBytes
HKEY_CLASSES_ROOT\EventSystem.EventSystem\PrivateData\FuckedBytes
Delete files:
krnlmgr.exe, krnlmngr.dll
Misc:
Juny files can be found in default system directory, which is one of the following: C:\Windows\System, C:\Windows\System32, C:\Winnt\System32.

     
Related Spyware Removal

 

 

Previous: JUpdate Trojan   Next: Juntador Trojan
| 1-9 | O | P | Q | R | S | T | U | V | W | X | Y | N | M | L | A | B | C | D | E | F | G | H | I | J | K | Z
Copyright © SpywareDot 2004-2009| Spyware Removal.  All rights reserved.