Remove Falsu
What is Falsu as well as dismissal instructions
Falsu is a worm which spreads by a Kazaa record pity network as well as IRC discuss channels regulating a mIRC client. Once executed, a bug silently installs itself to a system, modifies Kazaa settings, creates putrescent files with suggestive names in a Kazaa common printed matter as well as attempts to send itself to IRC users. However, a latter duty doesn’t work due bugs in Falsu code. The worm is written usually to widespread as well as thus does not lift any mortal payload. Falsu automatically runs upon each Windows startup.
Falsu primer removal:
Kill processes:
commando.exe, my_sister_nude.exe, winexec.exe, winsys.exe, winupdate.exe
Delete registry values:
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunwinexec
HKEY_CURRENT_USERSoftwareKazaaLocalContentDisableSharing=0
HKEY_CURRENT_USERSoftwareKazaaLocalContentdir0=012345:%Windir%Shared
HKEY_CURRENT_USERSoftwareKazaaLocalContentdir1=012345:%Windir%Shared
HKEY_CURRENT_USERSoftwareKazaaLocalContentdir2=012345:%Windir%Shared
HKEY_CURRENT_USERSoftwareKazaaLocalContentdir3=012345:%Windir%Shared
HKEY_CURRENT_USERSoftwareKazaaLocalContentdir4=012345:%Windir%Shared
HKEY_CURRENT_USERSoftwareKazaaLocalContentdir5=012345:C:
HKEY_CURRENT_USERSoftwareKAZAAResultsFilterfirewall_filter=0
HKEY_CURRENT_USERSoftwareKAZAAResultsFiltervirus_filter=0
Delete files:
commando.exe, my_sister_nude.exe, winexec.exe, winsys.exe, winupdate.exe, command.pif, command.scr, srvwin.scr
Delete directories:
C:WindowsShared
C:WinntShared
Misc:
Exact record location:
commando.exe, command.scr – C:
winexec.exe, command.pif, srvwin.scr – C:Windows or C:Winnt
winupdate.exe, winsys.exe – C:WindowsSystem, C:WindowsSystem32 or C:WinntSystem32
my_sister_nude.exe – C:Program FilesmIRCDownload
Article Source: レジストリクリーナー
Post a comment