Start to remove Virus:W97M/Ded.AA now!
Virus:W97M/Ded.AA description and removal instruction

Virus:W97M/Ded.AA

Free Virus:W97M/Ded.AA Scan

Technical information
Payload
Removal instructions

Technical information

The Virus:W97M/Ded.AA will install rogue security software Neotrek Url Extractor into the affected machines without users knowledge. The Virus:W97M/Ded.AA file size is 14336 bytes.

Payload

Once launched, the Virus:W97M/Ded.AA performs the following actions:

  • Download rogue security tool Neotrek Url Extractor from the following domains:
    http://www.neotreksoftware.com/
  • Modify the properties of the following files:
    %SYSTEMROOT%:\WINDOWS\winsxs\amd64_microsoft-windows-registryidle-agent_31bf3856ad364e35_6.1.7600.16385_none_7b622d76028dc002\\regidle.dll

    (14336 bytes; detected by HitMalware as " Virus:W97M/Ded.AA")
  • Removal instructions

    If your machine doesn't have antivirus/antispyware, please take the following steps to resolve the problems caused by Virus:W97M/Ded.AA:

    1. Replace the infected file regidle.dll for free by using regidle.dll repair tool - DLL Suite. See how to replace regidle.dll by using DLL Suite.

    2. Perform a full Virus:W97M/Ded.AA scan by using the latest antivirus/antispyware HitMalware.
    (Download Trial Version Now)

    MD5: 33225103322510


    How to replace regidle.dll by using DLL Suite

  • Download DLL Suite, install and run
  • Click "Start Scan" button to check regidle.dll file
  • Choose regidle.dll and click "More Information"
  • Download regidle.dll for free from the open web page
  • Save regidle.dll to its default folder to replace infected regidle.dll file.
  • Download Virus:W97M/Ded.AA Removal Tool Now

    Download Virus:W97M/Ded.AA Removal Tool Now