Please make sure you know what you are doing before performing any of the instructions on this site. You maybe better off downloading a proven spyware scanner and let the program do the cleaning. You may need anti-virus software as well and please allow up to 10 hours to get your system back on its feet again. Please feel free to ask questions, tell us the problem and we will help for FREE. We also have a great selection of SPYWARE and VIRUS prevention software available to try.
Removal instructions for bakain:
Bakain is a worm that spreads through network shares protected by weak passwords. Once executed, the parasite secretly installs itself to the system, runs a spreading routine and a payload. It changes some system settings and hides special Run and Find tools. The worm also contacts suspicious web sites. It automatically runs on every Windows startup.
Protect yourself from spyware and virus attacks PDF
Notes:
Stop processes:about linda.exe, lexplorer.exe, pcguard.exe, script.exe, service5.exe, systroy.exe, welcome.exe
Remove Registry values:
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRunhttp
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRunjava
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRunserve user
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRunservice
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRunusbtray
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionRunsystem checker
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWinlogonShell=explorer.exe [percentage]System[percentage] kz16fkservice5.exe
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWinlogonSystem=[percentage]System[percentage] kz16fkservice5.exe
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWinlogonUserinit=[percentage]System[percentage]userinit.exe,[percentage]Windir[percentage]pchealthpcguard.exe
HKEY_CURRENT_USERSoftwareMicrosoftWindows NTCurrentVersionWindowsload=[percentage]System[percentage] kz16fkservice5.exe
HKEY_CURRENT_USERSoftwareMicrosoftCommand ProcessorAutorun=echo off|[percentage]Windir[percentage]pchealthpcguard.exe|cls
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorerNoFind=1
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorerNoRun=1
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionSystemFileProtectionShowPopups=0
Remove files:
about linda.exe, lexplorer.exe, pcguard.exe, script.exe, service5.exe, systroy.exe, welcome.exe
Remove directories:
C:WINDOWSSystem32 kz16fkC:WINNTSystem32 kz16fk
Additional:Exact file location:lexplorer.exe - C:WINDOWS or C:WINNTsystroy.exe - C:WINDOWSinf or C:WINNTinfscript.exe - C:WINDOWSSystem32 or C:WINNTSystem32pcguard.exe - C:WINDOWSpchealth or C:WINNTpchealthservice5.exe - C:WINDOWS or C:WINNT; C:WINDOWSSystem32 kz16fk or C:WINNTSystem32 kz16fkwelcome.exe - C:Documents and SettingsAll UsersStart MenuProgramsStartup Bakain: