| 1.Overview
This Trojan logs the user’s
keystrokes. It is a Windows PE EXE file. It is written
in Visual C++. The packed file is approximately 12KB in
size. It is packed using ASPack. The unpacked file is
approximately 20KB in size. To completely purge
TrojanSpy.Win32.DKS from your computer, you need to
delete the files, folders, and Windows registry keys,
and registry values associated with
TrojanSpy.Win32.DKS.These files, folders, and registry
keys are respectively listed in the Files, Folders,
Registry Keys, and Registry Values sections on this
page.
For instructions on deleting the TrojanSpy.Win32.DKS
registry keys and registry values, see How to Remove
TrojanSpy.Win32.DKS from the Windows Registry.
For instructions on deleting the TrojanSpy.Win32.DKS
files and folders,
see How to Delete TrojanSpy.Win32.DKS Files (.exe, .dll,
etc.)
2.How to
Delete TrojanSpy.Win32.DKS Files (.exe, .dll, etc.)
The files and folders associated with
TrojanSpy.Win32.DKS are listed in the Files and Folders
sections on this page.
To delete the TrojanSpy.Win32.DKS
files and folders:
- Using your file explorer, browse to each file
and folder listed in the Folders and Files
sections.
Note: The paths use certain conventions
such as [%PROGRAM_FILES%]. These conventions are
explained here.
- Select the file or folder and press SHIFT+Delete
on the keyboard.
- Click Yes in the confirm deletion dialog box.
3.How to
Remove TrojanSpy.Win32.DKS from the Windows Registry
The Windows registry stores important
system information such as system preferences, user
settings, and installed programs details as well as the
information about the applications that are
automatically run at start-up. Because of this, spyware,
malware, and adware often store references to their own
files in your Windows registry so that they can
automatically launch every time you start up your
computer.
To effectively remove
TrojanSpy.Win32.DKS from your Windows registry, you must
delete all the registry keys and values associated with
TrojanSpy.Win32.DKS, which are listed in the Registry
Keys and Registry Values sections on this page.
IMPORTANT: Because the registry is a core
component of your Windows system, it is strongly
recommended that you back up the registry before you
begin deleting keys and values. For information
about backing up the Windows registry, refer to the
Registry Editor online help.
To remove the TrojanSpy.Win32.DKS
registry keys and values:
- On the Windows Start menu, click Run.
- In the Open box, type regedit and
click OK.
The Registry Editor window opens. This window
consists of two panes. The left pane displays
folders that represent the registry keys arranged in
hierarchical order. The right one lists the registry
values of the currently selected registry key.
- To delete each registry key listed in the
Registry Keys section, do the following:
- Locate the key in the left pane of the
Registry Editor window by sequentially
expanding the folders according to the path
indicated in the Registry Keys section.
For example, if the path of a registry key is
HKEY_LOCAL_MACHINE\software\FolderA\FolderB\KeyName1,
sequentially expand the HKEY_LOCAL_MACHINE,
software, FolderA, and FolderB folders.
- Select the key name indicated at the end of
the path (KeyName1 in the example above).
- Right-click the key name and select
Delete on the menu.
- Click Yes in the Confirm Key
Delete dialog box.
- To delete each registry value listed in the
Registry Values section, do the following:
- Display the value in the right pane of the
Registry Editor window by sequentially
expanding the folders in the left pane according
to the path indicated in the Registry Values
section and selecting the specified key name.
For example, if the path of a registry value is
HKEY_LOCAL_MACHINE\software\FolderA\FolderB\KeyName2\,valueC=,
sequentially expand the HKEY_LOCAL_MACHINE,
software, FolderA, and FolderB folders and
select the KeyName2 key to display the
valueC value in the right pane.
- In the right pane, select the value name
indicated after a comma at the end of the path (valueC
in the example above).
- Right-click the value name and select
Delete on the menu.
- Click Yes in the Confirm Value Delete dialog
box.
|