eHow launches Android app: Get the best of eHow on the go.

How To

How to Remove a Trojan Horse Actived .dll

Contributor
By Ty Arthur
eHow Contributing Writer
(0 Ratings)

The Delf Trojan, which most popular antivirus programs label the "Actived.dll" virus, can infiltrate your computer if you surf unsafe websites or download infected files. When your system is infected with the Trojan you will notice your computer operating at a greatly reduced speed and new files will appear on your hard drive. Before you can manually remove the Actived.dll virus files from your system, you first have to shut them down to prevent them from opening themselves.

Difficulty: Moderately Challenging
Instructions
  1. Step 1

    Bring up the Task Manager menu by pressing "Ctrl," "Alt" and "Delete" together. Click "Open Task Manager" and then click the "Processes" tab.

  2. Step 2

    Locate the process entry named "2[1].exe." Click the entry and then select "End Process." Remove the processes named "3[1].exe," "5[1].exe," "6[1].exe," "7[1].exe," "8[1].exe," "winform.dll," "cmdbcs.exe," "cmdbcs.dll," "d[1].exe," "deledomn.bat," "gadugadu.exe," "ghook.dll," "project1.exe," "msccrt.dll," "msccrt.exe," "servet.exe," "upxdndq.exe" and "upxdndq.dll."

  3. Step 3

    Shut down the Task Manager and then access the Start menu. Click the "Search" option. Search for and delete each of the files you ended the processes for earlier.

  4. Step 4

    Search for "syswm2" and delete the folder that appears in the search results. Enter "Regedit" into the search field and then double-click the registry editor icon.

  5. Step 5

    Expand the folders in the registry editor until you reach the folder named "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WindowsDown." Find the registry value at the right side of the window named "Description." Right-click the value and hit "Delete."

  6. Step 6

    Delete the values labeled "DisplayName," "Type," "Start," "ObjectName," "ImagePath," "NextInstance," "ErrorControl" and "Service."

  7. Step 7

    Open the registry folder named "Security." Right-click and delete the values labeled "Security" and "NextInstance."

  8. Step 8

    Navigate over to the registry folder named "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINDOWSDOWN\0000." Delete the values named "ConfigFlags," "ClassGUID," "Legacy," "Service" and "DeviceDesc."

  9. Step 9

    Shut down the registry editor. Restart your computer's operating system.

Tips & Warnings
  • The Actived.dll Trojan will attempt to download other malicious files to your computer that can cause further problems. Once the Trojan has been removed, you should still download and run an antivirus utility to make sure your system is clean of infections.
Subscribe

Post a Comment

Post a Comment

Related Ads

  • Have you done this? Click here to let us know.
I Did This
Get Free Computers Newsletters

Copyright © 1999-2009 eHow, Inc. Use of this web site constitutes acceptance of the eHow Terms of Use and Privacy Policy.   en-US Portions of this page are modifications based on work created and shared by Google and used according to terms described in the Creative Commons 3.0 Attribution License.

eHow Computers
eHow_eHow Technology and Electronics