Removal instructions Detection for this variant of Warezov has already been released in an urgent update for Kaspersky Anti-Virus databases.
If 'Proactive Protection' is enabled, Kaspersky Anti-Virus 6.0 is able to detect this malicious program without an update to the antivirus databases.
- Reboot the computer in Safe Mode (at the start of the boot sequence, press and hold F8, then choose ‘Safe Mode’ from the Windows boot menu. .
- Use Task Manager to search for the following process: serv.ex If such a process is found, terminate it.
- Manually delete the following files from the Windows root and system directories: %System%\e1.dll
%System%\regaufat.dll
%System%\wupstlnt.dll
%System%\cssewmpd
%Windir%\serv.dll
%Windir%\serv.s
%Windir%\serv.wax
%Windir%\serv.exe
- Delete the following registry values: [HKLM\Software\Microsoft\Windows\CurrentVersion\Run]
"serv"="%Windir%\serv.exe s"
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="wupstlnt.dll e1.dll"
- Reboot the computer as normal, and check that you have deleted all infected emails from all mail folders.
- Update your antivirus databases and perform a full scan of the computer (download a trial version of Kaspersky Anti-Virus.)