|
What is Tanexor and removal instructions
Tanexor is a worm that spreads through removable media. Once executed, the parasite secretly installs itself to the system and runs a payload. It terminates running processes of some antiviruses and security-related applications. It also opens a back door providing the attacker with unauthorized remote access to the compromised computer. The intruder can download arbitrary files and attack remote hosts. Tanexor is able to bypass the Windows Firewall. It runs as a service on every Windows startup.
Tanexor manual removal: Kill processes: down.exe, 1.exe
Delete registry values: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\power1_k
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\%System%\down.exe
Delete files: down.exe, 1.exe
Misc: Tanexor uses TCP port 8002.
Tanexor files can be found in default system directory, which is C:\WINDOWS\System32 or C:\WINNT\System32.
|
|
|
|
|