restart.exe - Dangerous

%windir%\restart.exe

Manual removal instructions:

Antivirus Report of %windir%\restart.exe:
%windir%\restart.exe Malware
%windir%\restart.exeDangerous
%windir%\restart.exeHigh Risk
%windir%\restart.exe
Restart.exe is a Trojan Backdoor.IRC.Ratsou.B.
Restart.exe spreads via open network shares.
Related files:
C:\Note.exe
%System%\Hid.exe
%System%\Explorer.dll
%System%\Iexplore.dll
%Windir%\Aim.dll
%Windir%\Boot.exe
%Windir%\C.dll
%Windir%\Crazy.exe
%Windir%\Dr.exe
%Windir%\Empavms.exe
%Windir%\Ipservers.dll
%Windir%\Java.dll
%Windir%\LibParse.exe
%Windir%\Lsass.exe
%Windir%\Miconfig.exe
%Windir%\Moo.dll
%Windir%\Msccl.dll
%Windir%\Msconig.exe
%Windir%\Nhtml.dll
%Windir%\Ratsou.exe
%Windir%\Regedit.dll
%Windir%\Restart.exe
%Windir%\Screen.dll
%Windir%\Sysboot.dll
%Windir%\Syste32.dll
%Windir%\Users.dll
%Windir%\Wind.dll
Adds the value:
"HID.EXE"="%System%\HID.EXE"
"lsass"="%Windir%\Debug\UserMode\lsass.exe"
to the Windows startup registry keys.
Removal:
Kill Restart.exe process and remove Restart.exe from Windows startup.

Remove restart.exe now!

Dmitry Sokolov:

I created UnHackMe in 2006 to fix the problem that antivioruses did not fix: detecting rootkits.

Since that time I work every day to fix the issues that antiviruses cannot.

If your antivirus have not helped you solve the problem, you should try UnHackMe.

We are a small company and you can ask me directly, if you have any questions.

Testimonials

You can read UnHackMe testimonials here.