|
What is Perfwo.b and removal instructions
Perfwo.b is a trojan that steals login names, passwords, character details and other confidential user information used in the Perfect World online computer game. Gathered data is transferred to a predetermined web server or sent to a predefined e-mail address. The trojan terminates some running antiviruses. It also injects malicious code into legitimate processes in order to record user keystrokes and hide its presence in the system. Perfwo.b secretly runs on every Windows startup.
Perfwo.b manual removal: Delete registry values: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\svchost
Delete files: cs.dll, wincab.sys, [X].sys
Misc: [X] is a random name.
Exact file location:
cs.dll, [X].sys - C:\WINDOWS\Temp or C:\WINNT\Temp
wincab.sys - C:\WINDOWS\System, C:\WINDOWS\System32 or C:\WINNT\System32
|
|
|
|
|