Services    Trojan info    Chat    Downloads      About Us      Contact  Us     Help Forum     Support Us    Search

Chupachbra
This trojan isn't the most advanced trojan around , basically it is a file server type trojan allowing the wannabe hackers to upload , download , delete files etc.
The most dangerous feature of this trojan is its multiple start up abilities , it can start up from a few different places so if you delete on place it will start up from another place , but don't worry , it can still be removed …..
How to remove :
First, you will want to open your c:\windows\win.ini file.
Towards the top you should see two lines reading:
run=winprot.exe
load=winprot.exe
Remove the section that reads 'winprot.exe', so the lines will read as:
run=
load=
Save and close win.ini.
Second, open regedit. You can do this by clicking your Start menu, and choosing Run. When the run window opens, type 'regedit' in the box (without the quotes) and click OK.
In the regedit window, you will see two half's. On the left hand panel, there will be a number of items with boxes next to them with small +'s.
To open an item, you simply click on the +.
Open the folders to follow this path:
HKEY_LOCAL_MACHINE\SOFTWARE\MicroSoft\Windows\CurrentVersion\Run
When you click on Run, the right hand panel will change. Find the item 'System Protect' = winprot.exe
Right click on this item, and choose Delete.
Next on the left hand side, in the same place click on RunServices (just below Run)
Again, Find the item 'System Protect' = winprot.exe
Right click on this item, and choose Delete.
Open the folders to follow this path:
HKEY_CURRENT_USER\SOFTWARE\MicroSoft\Windows\CurrentVersion\Run
When you click on Run, the right hand panel will change. Find the item 'System Protect' = winprot.exe
Right click on this item, and choose Delete.
Open the folders to follow this path:
HKEY_USERS\.Default\SOFTWARE\MicroSoft\Windows\CurrentVersion\Run
When you click on Run, the right hand panel will change. Find the item 'System Protect' = winprot.exe
Right click on this item, and choose Delete.
Close regedit and reboot your computer.
Once windows restarts, use Windows explorer to move into the folder
C:\windows\system\
and find the file winprot.exe, right click on the file, and choose Delete.