Sei sulla pagina 1di 3

Gphone.

exe removal instructions


Wednesday, January 7th, 2009 at 2:59 am
Gphone.exe description

Gphone.exe is worm which spreads via instant messengers. It usually affects Yahoo!
Messenger and Google Talk applications. Gphone.exe send a message and invites victims
to visit a website. If clicked upon, the link actually delivers a copy of Gphone.exe
infection. The worm delivers the following message:

“There is in the worst of fortune the best of chances for a happy change
There is only one way to happiness and that is to cease worrying about things which are
beyond the power of our will
The wisest mind has something yet to learn
The wise man in the storm prays God, not for safety from danger, but for deliverance
from fear
Happiness is a choice that requires effort at times
Action may not always bring happiness; but there is no happiness without action
Happiness is not a destination. It is a method of life
The best way to cheer yourself up is to try to cheer somebody else up
If you want truly to understand something, try to change it
I am a strong believer in luck and I find the harder I work the more I have of it
View my webcam (private) [LINK]”

Once it’s on board a computer, Gphone.exe blocks security tools. This enables
Gphone.exe to download and install other malwares.
Gphone.exe automatic detection

How to manually get rid of Gphone.exe

To get rid of spyware such as Gphone.exe you must block Gphone.exe sites, stop and
remove processes, unregister DLL files, search and remove all other Gphone.exe files and
registry utility. Follow the Gphone.exe detection and removal instructions below.

The most typical spyware removal method is to remove Gphone.exe by using "Add or
Remove Programs" service. However there may be hidden Gphone.exe files, running
processes and registries in your computer, so Gphone.exe may recreate all other files after
reboot.
Gphone.exe manual removal instructions

Block Gphone.exe sites:


rnd009.googlepages.com
Read more how to block Gphone.exe sites

Stop and remove Gphone.exe processes:


DEFAULT_NOT_SET.exe
New Folder.exe
gphone.exe
Read more how to kill Gphone.exe processes

Locate and delete Gphone.exe registry entries:


HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Work
groupCrawler\Shares\”shared” = “[ROOT FOLDER]\New Folder.exe”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\”Yahoo
Messengger” = “%System%\gphone.exe”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Winlogon\”Shell” = “Explorer.exe gphone.exe”
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Schedule\”AtTaskMaxH
ours” = “0″
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Schedule\”NextAtJobId
” = “2″
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Syste
m\”DisableTaskMgr” = “1″
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Syste
m\”DisableRegistryTools” = “1″
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explo
rer\”NofolderOptions” = “1″
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet
Explorer\Main\”Default_Page_URL” = “http://rnd009.googlepages.com/google.html”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet
Explorer\Main\”Default_Search_URL” = “http://rnd009.googlepages.com/google.html”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\”Search
Page” = “http://rnd009.googlepages.com/google.html”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\”Start
Page” = “http://rnd009.googlepages.com/google.html”
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\”Start Page” =
“http://rnd009.googlepages.com/google.html”
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\Control
Panel\”HomePage” = “1″
HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control
Panel\”HomePage” = “1″
Read more how to delete Gphone.exe registry entries

Detect and delete other Gphone.exe files:


%Windir%\gphone.exe
%System%\gphone.exe
%System%\DEFAULT_NOT_SET.exe
C:\Documents and Settings\All Users\Desktop\gphone.exe
%Temp%\gphone.exe
%System%\gphone.exe
%DriveLetter%\New Folder.exe
%DriveLetter%\gphone.exe
[ROOT FOLDER]\New Folder.exe
[ROOT FOLDER]\gphone.exe
%DriveLetter%\autorun.inf
%Windir%\Tasks\At1.job
[ROOT FOLDER]\autorun.inf
C:\disk.txt
%System%\autorun.ini
%System%\setting.ini
%Temp%\log_[TIME AND DATE].txt

We strongly recommend you to use spyware remover to track Gphone.exe and


automaticaly remove Gphone.exe processes, registries and files as well as other spyware
threats.

Potrebbero piacerti anche