Remove Pintae. Description and removal instructions

 
Title: Pintae

Type: Worms
Severity scale:Pintae severity is 61  (61 / 100)
 
Pintae is an Internet worm that spreads by e-mail through messages with infected attachments. Once the user opens such an attachment, the parasite secretly installs itself to the system and runs a spreading routine. It sends bogus e-mails to addresses in the Windows Address Book. The worm also copies itself to unprotected network shares. Then it runs a payload. Pintae changes some system settings and disables the Task Manager as well as the Registry Editor. It also terminates popular running antiviruses, firewalls, anti-spyware programs, trojan removers, registry and system utilities and other security-related processes. Pintae automatically runs on every Windows startup.


Related files: data.doc.exe, document.doc.exe, readme.doc.exe, taetae.txt.exe, autorun.bat, mskernell.bat, exit to dosprompt.pif, readme.scr

Pintae properties:
• Hides from the user
• Stays resident in background

Automatic Pintae removal:

remover for Pintae

Pintae manual removal:

Kill processes:
data.doc.exe, document.doc.exe, readme.doc.exe, taetae.txt.exe
Delete registry values:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\noypi_kang_astig
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\taetae
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\taengtae
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\tang_ina_mo
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFind=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFolderOptions=1
HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Restrictions NoFindFiles=1
Delete files:
data.doc.exe, document.doc.exe, readme.doc.exe, taetae.txt.exe, autorun.bat, mskernell.bat, exit to dosprompt.pif, readme.scr
Misc:
Files data.doc.exe, document.doc.exe, readme.doc.exe and taetae.txt.exe arrive attached to Pintae e-mail messages.

Exact file location:
readme.scr - unprotected network shares
exit to dosprompt.pif - C:\WINDOWS or C:\WINNT
autorun.bat - C:\WINDOWS\System, C:\WINDOWS\System32 or C:\WINNT\System32
mskernell.bat - C:\Documents and Settings\[Current User]\Start Menu\Programs\Startup

Other programs to remove Pintae:

• SUPERAntiSpyware - Review - Download
• CounterSpy - Review - Download
• Windows Defender - Review - Download

Information added: 08/11/06
Information updated: 08/11/06

Additional resources related to Pintae:

Attention: If you know or you have a website or page about Pintae removal, feel free to add a link to this list: add url




more resources

Post Comment:

Attention: Use this form only if you have additional information about Pintae parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.



Enter security code:

Latest spyware news:
Similar parasites: