News
Contributed by: Malcolm H.
Date: August 5, 2008
Mal Otorun1 Explained Mal Otorun1 is a malicious Trojan that was recently discussed in our article about how “USB Flash Drives are a perfect place for computer viruses to hide”. The unique behavior of the Mal Otorun1 is that it infects data storage devices and then replicates a virus onto any connected flash drives including USB thumb drives. As you can imagine, this parasite can easily be spread if the infected USB drive is used on another computer. Removing Mal Otorun1
If you have noticed or identified Mal Otorun1 or MalOtorun1 on your system or on your USB flash driven then you should perform a manual remove of Mal Otorun1 or utilize an antivirus or antispyware tool to automatically detect and remove Mal Otorun1. We recommend utilizing a reputable anti-virus or anti-spyware program that can scan, identify and remove the Mal Otorun1 Trojan. Below is the manual removal process for Mal Otorun1. The manual removal instructions are for informational purposes only. Use at your own risk. Manual Removal of Mal Otorun1 Before attempting to manually remove Mal Otorun1 or Mal_Otorun1 it is essential to be aware that this infection may have come from a USB drive. Removing any form of the AUTORUN.INF file from an attached USB drive or flash drive may remove Mal Otorun1 completely from your infected USB drive. It is possible that by disabling or editing a certain registry key will neutralize autorun.inf which may stop the Mal Otorun1 infection from being spread from an infected USB Flash drive. Step number 6 below is an example of this procedure. Please note: Disabling Autoplay may prevent any drive or removable media from being played automatically thus preventing infection or spread of Mal Otorun1 from a USB Flash drive.
If you are unsure of manually removing Mal Otorun1 then automatic removal of Mal Otorun1 may be performed utilizing a recent version of antivirus or antispyware software. It is suggested that you always run a copy of trust-worthy antispyware or antivirus software at all times to detect and remove infections such as Mal Otorun1. |
|||||
Software Downloads

Removal of Mal Otorun1 or Mal_Otorun1 is essential to prevent the spread of this malicious infection onto other systems or risking damage to stored data. Trend Micro has reported that Mal Otorun1 has increased the amount of infections for flash drives so you must take this Trojan infection seriously and remove it as soon as possible.

User Comments
After go to properties by right clicking the folder and select the attributes "Read only" and "Hidden". This prevents Mal_Otorun from propagating onto your flash drive.
Repeat the process for the autorun folder and do it for "RECYCLER" (quotes not included).
Mal_Otorun or W32.Dotex creates a regedit key which disables your computer into accessing safe mode. Click run and type regedit. Then, delete all of these keys:
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWin dows NTCurrentVersionImage File Execution Options360rpt.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Options360Safe.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Options360tray.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsadam.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsAgentSvr.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsAppSvc32.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsArSwp.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsAST.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsautoruns.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsavconsol.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsavgrssvc.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsAvMonitor.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsavp.com
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsavp.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsCCenter.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsccSvcHst.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsEGHOST.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsFileDsty.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsFTCleanerShell.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsFYFireWall.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsHijackThis.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsIceSword.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsiparmo.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsIparmor.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsisPwdSvc.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionskabaload.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKaScrScn.SCR
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKASMain.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKASTask.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKAV32.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKAVDX.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKAVPF.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKAVPFW.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKAVSetup.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKAVStart.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKISLnchr.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKMailMon.exe
"Debugger" =- "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKMFilter.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKPFW32.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKPFW32X.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKPfwSvc.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKRegEx.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKRepair.com
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKsLoader.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKVCenter.kxp
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKvDetect.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKvfwMcl.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKVMonXP.kxp
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKVMonXP_1.kxp
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionskvol.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionskvolself.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKvReport.kxp
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKVScan.kxp
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKVSrvXP.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKVStub.kxp
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionskvupload.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionskvwsc.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKvXP.kxp
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKvXP_1.kxp
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKWatch.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKWatch9x.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKWatchX.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsloaddll.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsMagicSet.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsmcconsol.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsmmqczj.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsmmsk.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsNavapsvc.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsNavapw32.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsnod32.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsnod32krn.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsnod32kui.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsNPFMntor.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsPFW.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsPFWLiveUpdate.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsQHSET.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsQQDoctor.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsQQKav.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsRas.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsRav.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsRavMon.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsRavMonD.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsRavStub.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsRavTask.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsRegClean.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsrfwcfg.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsrfwmain.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsrfwsrv.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsRsAgent.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsRsaupd.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsrstrui.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsruniep.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionssafelive.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsscan32.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsshcfg32.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsSmartUp.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsSREng.EXE
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionssymlcsvc.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsSysSafe.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsTrojanDetector.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsTrojanwall.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsTrojDie.kxp
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsUIHost.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsUmxAgent.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsUmxAttachment.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsUmxCfg.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsUmxFwHlp.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsUmxPol.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsupiea.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsUpLive.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsUSBCleaner.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsvsstat.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionswebscanx.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsWoptiClean.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
Go to these keys: You will need to create these keys because Mal_Otorun has deleted these, disallowing the computer booting into safe mode. HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSa feBootMinimal{4D36E967-E325-11CE-BFC1-08002BE10318 }
HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlS afeBootNetwork{4D36E967-E325-11CE-BFC1-08002BE1031 8}. Follow steps by the writer after these and Mal_Otorun should be gone.
After go to properties by right clicking the folder and select the attributes "Read only" and "Hidden". This prevents Mal_Otorun from propagating onto your flash drive.
Repeat the process for the autorun folder and do it for "RECYCLER" (quotes not included).
Mal_Otorun or W32.Dotex creates a regedit key which disables your computer into accessing safe mode. Click run and type regedit. Open Regedit and go to the keys. You will need to create these keys because Mal_Otorun has deleted these, disallowing the computer booting into safe mode. Then, delete all of these keys:
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWin dows NTCurrentVersionImage File Execution Options360rpt.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Options360Safe.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Options360tray.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsadam.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsAgentSvr.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsAppSvc32.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsArSwp.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsAST.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsautoruns.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsavconsol.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsavgrssvc.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsAvMonitor.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsavp.com
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsavp.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsCCenter.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsccSvcHst.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsEGHOST.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsFileDsty.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsFTCleanerShell.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsFYFireWall.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsHijackThis.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsIceSword.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsiparmo.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsIparmor.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsisPwdSvc.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionskabaload.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKaScrScn.SCR
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKASMain.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKASTask.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKAV32.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKAVDX.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKAVPF.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKAVPFW.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKAVSetup.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKAVStart.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKISLnchr.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKMailMon.exe
"Debugger" =- "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKMFilter.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKPFW32.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKPFW32X.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKPfwSvc.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKRegEx.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKRepair.com
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKsLoader.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKVCenter.kxp
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKvDetect.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKvfwMcl.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKVMonXP.kxp
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKVMonXP_1.kxp
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionskvol.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionskvolself.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKvReport.kxp
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKVScan.kxp
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKVSrvXP.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKVStub.kxp
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionskvupload.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionskvwsc.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKvXP.kxp
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKvXP_1.kxp
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKWatch.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKWatch9x.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsKWatchX.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsloaddll.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsMagicSet.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsmcconsol.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsmmqczj.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsmmsk.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsNavapsvc.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsNavapw32.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsnod32.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsnod32krn.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsnod32kui.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsNPFMntor.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsPFW.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsPFWLiveUpdate.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsQHSET.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsQQDoctor.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsQQKav.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsRas.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsRav.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsRavMon.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsRavMonD.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsRavStub.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsRavTask.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsRegClean.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsrfwcfg.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsrfwmain.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsrfwsrv.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsRsAgent.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsRsaupd.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsrstrui.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsruniep.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionssafelive.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsscan32.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsshcfg32.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsSmartUp.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsSREng.EXE
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionssymlcsvc.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsSysSafe.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsTrojanDetector.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsTrojanwall.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsTrojDie.kxp
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsUIHost.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsUmxAgent.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsUmxAttachment.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsUmxCfg.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsUmxFwHlp.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsUmxPol.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsupiea.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsUpLive.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsUSBCleaner.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsvsstat.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionswebscanx.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe"
¢HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsWoptiClean.exe
"Debugger" = "%Program Files%Common FilesMicrosoft Sharedpxpfern.exe" HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSa feBootMinimal{4D36E967-E325-11CE-BFC1-08002BE10318 }
HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlS afeBootNetwork{4D36E967-E325-11CE-BFC1-08002BE1031 8}. Follow steps by the writer after these and Mal_Otorun should be gone.
My friend, have teh NOD32 and doens't detected the virus, I have the TRend and too detected the virus, please, can you tell me what is the correct antivirus for use, I am from Mexico, I don't speak english.
Pls help if there is more info available!