TUCoPS :: Hacking Techniques :: fix17.txt

Fixing SubSeven 1.7 BKI:

HackFix - SubSeven - Fix v1.7

NOTE: You should print this page for reference before starting.

Step one is to go to your Start menu, click Shutdown, and select "Restart
the computer in MS-DOS mode", then click ok.
When you do this, you should be in MS-DOS looking at a c:\windows\ prompt.
This version places itself at C:\windows\kernel16.dl

Simply type
del kernel16.dl
This will delete the trojan.

If this errors, you may need to type
attrib kernel16.dl -h
to remove the hidden flag, and then type the delete command above.

Type exit to return to windows.

Next, click Start, and go to Run. In the box, type regedit and click OK.
When regedit starts, you will see a file-like tree on the left hand panel.
Open the folders to follow the path:
At the end, click on 'RunServices' once, and the right hand panel should
On the right hand side of Regedit, look for the item titled
Kernel16 = "kernel16.dl" Right click on that line only and choose delete.
Close regedit and reboot your PC.

Your now disinfected!

