The Trojan horse PSW.Banker6.AWGZ is a malicious application that is categorized as a severe Trojan horse virus. This dangerous Trojan belongs from the famous family of the PSW.Banker6 family of viruses. Once installed, this malicious application change the desktop background, home page, and default browser on your system. Besides that, this Trojan infection stops you from installing any new program. There are a number of malicious activities took place once this Trojan horse installed on any PC. The Trojan horse PSW.Banker6.AWGZ can open the backdoor for additional parasites, and disable the antivirus program along with the other security tools. This malicious application is also capable of change all of your default system settings, and deny the access to many important programs installed on your computer. The basic aim of the developers of this Trojan horse application is to steal the money of the users by stealing the confidential data. Besides the above mentioned activities, this Trojan infection also makes your system extremely slow.
The Manual Removal of Trojan horse PSW.Banker6.AWGZ
Once the computer is compromised to this Trojan horse infection, you need to delete this virus quickly. You can manage to remove this virus by either using a powerful automatic removal tool, or with the help of the manual removal method. If you choose to remove this infection manually, you have to follow the instructions mentioned below:-
Start the System in Safe Mode
You have to reboot the system in order to terminate the normal mode. While the system restarted, you have to press F8 key to see the list of boot options from which you need to select the safe mode option.
Kill the Associated Processes
Once the system starts operating in the safe mode, you have to use the Ctrl+Alt+Delete keys to access the windows task manager. In the task manager, you have to click on the processes tab to see a list of running processes. You need to delete the following associated processes of this virus:-
- %AppData%\[RANDOM CHARACTERS]\[RANDOM CHARACTERS].exe
Delete the Associated Files
Once the related process of the Trojan horse PSW.Banker6.AWGZ removed, you have to delete the files associated with this Trojan horse infection. Following are the suspicious files that are needed to be removed:-
- %Desktopdir%\Trojan horse PSW.Banker6.AWGZ.lnk
- %Programs%\Trojan horse PSW.Banker6.AWGZ\Trojan horse PSW.Banker6.AWGZ.lnk
Reverse the Modification in the Windows Registry
Once you are done with the processes, and files, you have to delete the malicious entries created by this Trojan horse virus in the windows registry. You have to open the registry editor by clicking on the start button, select run option and type “regedit” to access the registry editor. Find and delete the following entries from the windows registry:-
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Trojan horse PSW.Banker6.AWGZ\DisplayIcon %AppData%\[RANDOM CHARACTERS]\[RANDOM CHARACTERS].exe,0
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Trojan horse PSW.Banker6.AWGZ
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Trojan horse PSW.Banker6.AWGZ\UninstallString “%AppData%[RANDOM CHARACTERS][RANDOM CHARACTERS].exe” -u
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce\[RANDOM CHARACTERS] %AppData%\[RANDOM CHARACTERS]\[RANDOM CHARACTERS].exe
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Trojan horse PSW.Banker6.AWGZ\ShortcutPath “%AppData%\[RANDOM CHARACTERS]\[RANDOM CHARACTERS].exe” -u
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Trojan horse PSW.Banker6.AWGZ\DisplayName Trojan horse PSW.Banker6.AWGZ
Close the registry editor, and restart the system in the normal mode. Update the antivirus program and run a complete system scan to remove the infections.