The WORM_KELIHOS.NB is a malicious application that installed millions of computers all over the world automatically. It is categorized as a Trojan virus, and developed specifically to steal the personal as well as financial information about the user.  This information includes credit card details, passwords, logins, shopping preferences, and browsing history. It has the ability to occupy the resources due to which the performance of the infected computer affects negatively. Once it is installed on your computer, it stops most of the useful applications installed on your computer due to which your daily tasks badly affected. The WORM_KELIHOS.NB also slows down the speed of your computer. This dangerous Trojan is extremely dangerous as it changes the windows firewall, and disable current antivirus program installed on the PC. Mostly this malicious Trojan spreads through spam email attachments, freeware installation, accepting online offers, social media links, and sharing the resources with other computers on the same network. Once it is detected on any computer, you have to delete it without wasting the time, because if you get rid of this tricky virus soon, you can minimize the scale of loss.

Manual Removal Process of WORM_KELIHOS.NB

Once the WORM_KELIHOS. NB is detected on your computer you have to get rid of this virus at your earliest. You can either choose a reliable automatic WORM_KELIHOS. NB removal tool, or follow the complicated instructions of the manual removal method. The manual removal steps are mentioned below:-

Start the Computer in Safe Mode

The first step of the manual removal method is to reboot the computer in safe mode. In this regard, you need to restart the PC, and press F8 key to see the boot options where you have to choose the safe mode option and hit the enter key.

Delete the Malicious Processes

Once the computer starts in the safe mode, the next step is to kill the malicious processes attached to the WORM_KELIHOS. NB. You have to hold Ctrl+Alt+Delete keys to start the task manager, and press the processes tab to find as well as remove the following malicious processes associated with this malware.

  • %AppData%\[RANDOM CHARACTERS]\[RANDOM CHARACTERS].exe

Delete the Files and Folders

When you are done with the process issue, you need to get rid of the following files and folders:-

  • %Desktopdir%\WORM_KELIHOS.NB.lnk
  • %Programs%\WORM_KELIHOS.NB\WORM_KELIHOS.NB.lnk

Delete Registry Entries

The final step of manual removal process is to clean the windows registry by deleting the malicious entries created by this dangerous parasite. You have to open the registry editor by clicking on the start button, choosing the Run option, type regedit in the box, and press ok button. Once the registry editor started, you can easily remove the following entries by selecting them one by one:-

  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\WORM_KELIHOS.NB\DisplayIcon %AppData%\[RANDOM CHARACTERS]\[RANDOM CHARACTERS].exe,0
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\WORM_KELIHOS.NB
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\WORM_KELIHOS.NB\UninstallString “%AppData%[RANDOM CHARACTERS][RANDOM CHARACTERS].exe” -u
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce\[RANDOM CHARACTERS] %AppData%\[RANDOM CHARACTERS]\[RANDOM CHARACTERS].exe
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\WORM_KELIHOS.NB\ShortcutPath “%AppData%\[RANDOM CHARACTERS]\[RANDOM CHARACTERS].exe” -u
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\WORM_KELIHOS.NB\DisplayName WORM_KELIHOS.NB

After removing the registry entries, you have to close the registry editor and start the computer in the normal mode to see the effect of changes you have made.

How to Remove WORM_KELIHOS.NB?
Tagged on:                 

Leave a Reply

Your email address will not be published. Required fields are marked *

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>