Pintae manual removal:
Kill processes:
data.doc.exe, document.doc.exe, readme.doc.exe, taetae.txt.exe
Delete registry values:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\noypi_kang_astig
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\taetae
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\taengtae
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\tang_ina_mo
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFind=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFolderOptions=1
HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Restrictions NoFindFiles=1
Delete files:data.doc.exe, document.doc.exe, readme.doc.exe, taetae.txt.exe, autorun.bat, mskernell.bat, exit to dosprompt.pif, readme.scr
Misc:Files data.doc.exe, document.doc.exe, readme.doc.exe and taetae.txt.exe arrive attached to Pintae e-mail messages.
Exact file location:
readme.scr - unprotected network shares
exit to dosprompt.pif - C:\WINDOWS or C:\WINNT
autorun.bat - C:\WINDOWS\System, C:\WINDOWS\System32 or C:\WINNT\System32
mskernell.bat - C:\Documents and Settings\[Current User]\Start Menu\Programs\Startup
Post Comment: