|
 |
|
Remove Trojan.Xema worm
Xema works as both trojan and worm. It infects computers secretly and downloads other malwares. Xema brings additional payload too. Xema checks various data about the infected computer and sends it to a remote attacker. This malware is dangerous because it works secretly and keeps infecting other computers. It spreads further by infecting UBS keys.
Xema might be difficult to find and remove, but it’s important to delete Xema till it hasn’t done much damage. It may infect all the executable files (*.exe) located on a machine.
Xema modifies registry keys and system files in order to run on startup.
Xema is Dangerous
Xema is a Trojan parasite
Xema may display fake security & messages
Xema may display numerous annoying advertisements
Xema may be remotely controlled by a malicious person
Xema may spread additional spyware
Xema may repair its files, spread or update by itself
Xema may prove difficult or impossible to remove
Xema violates your privacy and compromises your security
Stop these Xema processes:
windfire2.exe
w1234.exe
serlibk.exe
windfire.exe
msregsv.exe
Disable these Xema DLL files::
inter32.dll
shell64.dll
Remove these Xema Registry Entries:
HKEY_CLASSES_ROOT\CLSID\{AEB6717E-7E19-11d0-97EE-00C04FD91972}
Remove these Xema files:
c_10810.nls
c_19460.nls
c_20462.nls
inter32.dll
shell64.dll
shlmon.exe
w1234.exe
serlibk.exe
windfire.exe
windfire2.exe
msregsv.exe
config\systemevent.log
config\software.chk
config\Temporary Internet Files\.iau
\Recycled\deskinf.pif
\Recycled\deskinf.ini
\Recycled\~INFO2
\Recycled\~WR00001.doc
\Recycled\~WR00002.doc
\Recycled\windfire2.exe
\autorun.inf
|
| | |
 |
|
|