The Troj/FakeAV-GNL is another addition in the family of Trojan horse viruses, and developed to steal the money of innocent computer users that are using the windows based computers. This malicious application starts collecting your information by using various methods as soon as installed on your system. This can be done by taking screen shots, keyloggers, and other techniques. This information is of two types, one is your personal details that include your complete name, address, and credit card details, and the other part of the information is recording your browsing habits and shopping preferences. Besides all of the above mentioned malicious activities, this dangerous Trojan virus is also engaged in running pop-up ads on the screen of your computer which makes it hard for you to browse through.

 

The Instructions for Manual Removal of Troj/FakeAV-GNL

After knowing that the TrojHYPERLINK you have to remove this malicious application from your system quickly. You have got the option of removing this dangerous virus by using any automatic removal tool, or by following the manual removal instructions. The manual removal method of this trojan horse virus is complicated which consists of the following steps:-

 

Select the Safe Mode

The first step of this complicated process is to start the system in the safe mode. You have to reboot the system when your computer is running in the normal mode by just restarting it. When the system is in restarting process, use F8 key to see the boot option menu, and select the safe mode option from the available list, before press Enter key to boot your computer in the safe mode.

Remove the Associated Processes

The next thing which you need to do is, removal of the processes associated with the Troj/FakeAV-GNL. Just open the task manager window which can be accessible by pressing the Ctrl+Alt+Delete keys together. Once you are able to access the task manager window, you have to click on the processes tab, where a list of running processes is available from which you have to delete the following processes related to malicious application:-

  • %AppData%\[RANDOM CHARACTERS]\[RANDOM CHARACTERS].exe

Remove the Files and Folders

The next step of manual removal process is to remove the files, and folders associated with this dangerous Trojan horse. In this regard following are some suspicious files that you need to delete immediately:-

  • %Desktopdir%\Troj/FakeAV-GNL.lnk
  • %Programs%\Troj/FakeAV-GNL\Troj/FakeAV-GNL.lnk

Remove the Corrupt Registry Entries

The manual removal isn’t completed until you don’t remove the registry entries created in the windows registry by this malicious Trojan virus. You have to open the registry editor by using the Regedit command through the Run option available in the Start menu. Once the registry editor is accessed, you have to get rid of the following entries before closing the registry editor:-

  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Troj/FakeAV-GNL\DisplayIcon %AppData%\[RANDOM CHARACTERS]\[RANDOM CHARACTERS].exe,0
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Troj/FakeAV-GNL
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Troj/FakeAV-GNL\UninstallString “%AppData%[RANDOM CHARACTERS][RANDOM CHARACTERS].exe” -u
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce\[RANDOM CHARACTERS] %AppData%\[RANDOM CHARACTERS]\[RANDOM CHARACTERS].exe
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Troj/FakeAV-GNL\ShortcutPath “%AppData%\[RANDOM CHARACTERS]\[RANDOM CHARACTERS].exe” -u
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Troj/FakeAV-GNL\DisplayName Troj/FakeAV-GNL

 

 

 

How to Remove Troj/FakeAV-GNL?
Tagged on:             

Leave a Reply

Your email address will not be published. Required fields are marked *

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>