Manual Removal of W32/Rabbit.FR Trojan » [Default Username].exe
This Trojan Copies its file(s) to Documents and Settings\Default User folder as hidden files or active non-hidden files.
This trojan information updated on September 23, 2009.
Other names of W32/Rabbit.FR Trojan:
This trojan is also known as Trojan.Win32.Rabbit.fr, TrojanDownloader:Win32/Cutwail.AI, Trojan.Pandex.
Download Registry, Taskmanager and Folder Options Repair Tool
W32/Rabbit.FR Trojan Manual Removal Instructions
Recommend Removal from Safe Mode:
How to Start in Safe mode:
Restart your Computer, Press F8 Repeatedly, when your Screen turns on, Select Safe mode, press enter.
End the Following Active Process Before Removal
- [ Kill the Process, Use Killbox if your Access Denied ]
- %Documents and Settings\Default User\[Default Username].exe
[ No Exact Information about Files, search above related files in Program files Folder ]
If you have any of these files in running process from task manger, end the process before removal.
Note: if task manager is disabled, Download the following file, Click to Download - Enable Registry.reg[ Right Click - Save Target As/Linked Content As ]
Open it with Regedit.exe [%system32\regedit.exe], then it Confirms Add to registry Yes or No, Confirm Yes, then click Ok.
Click Start, Run,Type regedit,Click OK.
Note: If the registry editor fails to open the threat may have modified the registry to prevent access to the registry editor.
- Download this UnHookExec.inf, [ Right Click - Save Target As/Linked Content As ]
- Save it to your Windows desktop.
- Do not run it at this time, download it only.
- After booting into the Safe Mode or VGA Mode
- Right-click the UnHookExec.inf file and click Install. [This is a small file. It does not display any notice or boxes when you run it.]
- Or Download Regfile to enable Registry editor
- Download Registry Enabler [ Right click - Save Target As ]
- Open it with Registry editor
Delete The Entries
HKEY_USERS\S-1-5-21-XXXXXXXXXX-XXXXXXXXXX-XXXXXXXXX-XXXX\Software\Microsoft\Windows\CurrentVersion\Run
Delete file entries from right side
Search Registry For W32/Rabbit.FR Trojan File Names listed above to remove completely,
Edit Menu - Find, enter Keyword and remove all value that find in search.
Recommended Removal Tools:
Kaspersky Antivirus or Internet Security [Shareware]
Spyware Doctor [Shareware]
AVG Antivirus [Freeware]
Killbox [Freeware]
Written by magakos on October 22nd, 2009 with no comments.
Read more articles on W32/Rabbit.EL and W32/Rabbit.FR and manual removal and removal of trojan and otherSoftware and Windows.















