How to Uninstall the Grum Trojan Horse
Microsoft’s Windows operating systems have become notorious for the many viruses and malware applications that are capable of infecting the system. One such threat is the Grum Trojan Horse. Like most trojan horses, the Grum Trojan disguises itself as a harmless email attachment or Internet download. An attack by the Grum Trojan Horse poses as an invitation that comes from Microsoft to download the beta 2 version of Microsoft's Internet Explorer 7.0. The email will be disguised as an Internet Explorer download from admin@microsoft.com. It will have "Internet Explorer 7 Downloads" in the subject line, and the body of the email will contain an image inviting you to make this download. If you click on this image, a file called "ie7.0.exe" will be downloaded. This trojan downloader will infect your computer with the Win32.Grum worm.
Instructions
-
Disable System Restore
-
1
Disable System Restore to prevent your computer from reverting to previous settings after you have uninstalled the Grum Trojan virus. Here's how:
-
2
Click on the START button located at the bottom-left corner of the desktop. Next, right-click on the MY COMPUTER icon and click PROPERTIES.
-
-
3
Select the SYSTEM RESTORE tab in the Properties window. Check the option labeled TURN OFF SYSTEM RESTORE. Click on APPLY.
-
4
Click YES to delete all saved restore points. Click OK. System Restore has now been disabled. (IMPORTANT: See Warning Below)
Uninstall the Grum Trojan Horse
-
5
Reboot your computer in Safe Mode. Safe Mode can be initiated by hitting the F8 key on your keyboard while your computer is booting, and then select the "Safe Mode" option.
-
6
Click on the START button and then click on RUN. Once the Run window opens, type in "regedit "and then click on "OK." This will open the Registry Editor.
-
7
Use the plus signs to navigate to the following registry entry: HKEY_LOCAL_MACHINE\Software\ Microsoft\Windows \CurrentVersion\Run.
-
8
Right-click on the following entry, and then remove it: Firewall auto setup = %User Temp%\winlogon.exe". (%UserTemp% represents the Temp folder, which is usually located in C:\Documents and Settings\username\Local Settings\Temp. )
-
9
Repeat the above step for the following registry entry: HKEY_CURRENT_USER\Software\Microsoft\Windows \CurrentVersion\Run.
-
10
Close the Registry Editor. Next, reboot the computer in Normal Mode. Run an up-to-date antivirus program to make sure your computer is clean.
-
11
Turn your System Restore back on. And you are done!
-
1
Tips & Warnings
By turning off system Restore , you will delete all your existing restore points, and won't be able to undo or track changes on your PC.