What is esentutl64.exe, How to remove esentutl64.exe
Saturday, June 12th, 2010esentutl64.exe is a harmful program.
It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. |
Name: esentutl64
Filename: esentutl64.exe
Registry key:
HKEY_CLASSES_ROOT\exefile\shell\open\command | @=”\”C:\DOCUME~1\user\LOCALS~1\Temp\esentutl64.exe\” /START \”%1\” %*”
Command: %Temp%\esentutl64.exe
Startup Type: File associations
Combofix/RSIT Line:
.exe – open – “C:\DOCUME~1\comp\LOCALS~1\Temp\esentutl64.exe” /START “%1” %*
Description: trojan FakeAlert that installed with Defense Center. Defense Center is a rogue (fake) antispyware program.
How to remove: use these Defense Center removal instructions or the steps below.
1. Download fix.zip from here, unzip it. Double Click fix.reg and click YES for confirm.
2. Download OTM by OldTimer from here and save to your desktop.
Run OTM, copy,then paste the following text in “Paste Instructions for Items to be Moved” window (under the yellow bar):
:reg
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
“Defense Center”=-
:files
C:\Program Files\Defense Center
Click the red Moveit! button. Close OTM.
3. Download TDSSKiller from here and unzip to your desktop. Open tdsskiller folder and right click to TDSSKiller, select Rename. Type something like 123myname and press Enter. Double click it and follow the prompts.
4. Download Malwarebytes Anti-malware. Install and perform a scan and let it remove what it found. Reboot afterwards (important).