Monday, November 3, 2008

firefox.exe malware removal

Symptoms:
If you find firefox.exe process in task manager with around 3100k size than it is malware.
If you run Ccleaner than it gives message of opened firefox although firefox is not running.

To remove from the system(Windows).
1. boot system in safe mode.
2. run regedit
3. search for the "Stubpath" enetry
4. Mostly It shows "SecSecurity.exe"
5. Delete all "Stubpath" entries from registry ( Be Careful while edit Registry)
6. also remove SecSecurity.exe from Windows\System32
7. Boot in Normal mode
8. check in task manager not entry of firefox.exe around 3100k ( real Firefox entry is more in size)

No comments: