Remove Imaut.u

Posted on November 24th, 2010 in Common Technique by admin

What is Imaut.u as well as dismissal instructions

Imaut.u is an Internet worm which spreads by present messages regulating AIM, Yahoo! Messenger as well as Windows Live Messenger programs. The parasite’s messages enclose links to antagonistic web pages. Once a user clicks upon such a link, a worm gets personally downloaded as well as commissioned to a system. Then it runs a swelling slight as well as a payload. Imaut.u changes a Internet Explorer default home page, disables a Task Manager as well as a Registry Editor as well as modifies sure Yahoo! Messenger settings. It additionally attempts to open antagonistic web sites as well as shift confidence settings of present messaging programs. Furthermore, it can cancel using security-related processes. The bug runs upon each Windows startup.

Imaut.u primer removal:
Kill processes:
svchost.exe, svchost32.exe
Delete registry values:
HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRunTask Manager
HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRunYahoo Messenger
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesSystemDisableRegistryTools=1
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesSystemDisableTaskMgr=1
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorerNoRun=1
HKEY_CURRENT_USERSoftwareMicrosoftInternet ExplorerMainStart Page=[site address]
HKEY_CURRENT_USERSoftwarePoliciesMicrosoftInternet ExplorerControl PanelHomepage=1
HKEY_CURRENT_USERSoftwareYahoopagerViewYMSGR_buzzContent URL=[site address]
HKEY_CURRENT_USERSoftwareYahoopagerViewYMSGR_LaunchcastContent URL=[site address]
Delete files:
svchost.exe, svchost32.exe
Misc:
[site address] is an residence of a web site upon a quicknews.info domain.

Exact record location:
svchost.exe – C:WINDOWSSystem or C:WINNTSystem
svchost32.exe – C:WINDOWSSystem32 or C:WINNTSystem32


Article Source: レジストリクリーナー

Post a comment