|
What is Sacrep and removal instructions
Sacrep is a trojan designed to log user keystrokes and send recorded data to the hacker by e-mail. Once executed, Sacrep drops an executable with Japanese name to the default system directory (C:\Windows\System, C:\Windows\System32 or C:\Winnt\System32) and modifies the registry, so the threat could run on every OS startup.
Sacrep manual removal: Delete registry values: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\[file_name].exe=%System%\[file_name].exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\drv32
|