|
What is Revrs and removal instructions
Revrs is a dangerous backdoor that gives the attacker full remote unauthorized access to a compromised computer. The hacker can execute different commands, run programs, record user keystrokes, manage files, modify system settings, download and install additional software, steal user sensitive information, control a computer and its devices. Revrs stores its files in C:\Windows\System or C:\Winnt\System directory. It runs on every Windows startup. The backdoor has the ability to update itself via the Internet.
Revrs manual removal: Kill processes: msgsrv16.exe, directx3d.exe
Delete registry values: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\DirectX 3D Service=%Windir%\System\directx3d.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Service386Shell=%Windir%\System\msgsrv16.exe
Delete files: msgsrv16.exe, directx3d.exe
|
|
|
|
|