My system got infected by HKU\S-1-5-21 virus. I have no clue how it get inside my computer? My system was working very slow and most of the program failed to work. My PC often get freeze and stop responding. I have scanned my system and found HKU\S-1-5-21 virus. My anti-virus can detect this threat but cannot remove it completely. It keep coming back after removal. Tried several methods and anti-virus tools but still unable to delete HKU\S-1-5-21 from my machine. Please help me to completely remove HKU\S-1-5-21 from my computer.
HKU\S-1-5-21 is a harmful Trojan infection. This brutal threat normally infiltrate your computer via freeware application download, shareware, peer to peer files sharing, Spam mail attachments, infected removal media, drive by download and by visiting malicious websites. This nasty Trojan horse is capable of trespassing your anti-virus scan and can easily get installed without any notification. Once inside your computer, it will start doing several malicious activities that will downgrade your PC performance. Initially it will infect your windows registry for getting automatic restart upon booting of your system. HKU\S-1-5-21 also uses root-kit capabilities to hook itself very deep in your computer system and stay undetected and secured for a long period of time.
Later, HKU\S-1-5-21 can also disable some of the important components of your computer system like Windows task manager, anti-virus program, Windows firewall, registry editor and other important and legitimate applications. This is a very aggressive Trojan infection which can also bring some more threats and bugs into your computer. This perilous infection is also related to system crash and can also slow down your system speed. It draws too much of CPU resources which causes computer slow down and even take it to crash level. HKU\S-1-5-21 can steal your personal information including Bank account and credit card information, login Id, passwords etc. and send to remote hackers. This perilous Trojan virus can also open backdoor on your system for other threats and malware. You are suggested to remove HKU\S-1-5-21 before any severe harm.
Steps to Remove HKU\S-1-5-21
Step 1>> How to Boot Windows in Safe Mode to isolate HKU\S-1-5-21
Step 2>> How to View Hidden Files created by HKU\S-1-5-21
for Windows XP
- Exit all Program and Go to Desktop
- Select My Computer icon and Double Click to Open it
- Click on the Tools Menu and now select and Click on Folder Options.
- Select on View Tab that appears in New Window.
- Check mark on the box next to Dispaly the Contents of System Folders
- Now Check the box in order to Show Hidden Files and Folders
- Now press on Apply and OK to close the Window.
- As soon as these steps are performed, you can view the files and folders that were created by HKU\S-1-5-21 and hidden till now.
for Windows Vista
- Minimize all Window and Go to Desktop
- Click on the Start Button which can be found in lower lef Corner having Windows Logo
- Click on the Control Panel on the Menu and Open it
- Control Panel can be opened in Classic View or Control Panel Home View.
- If you have Selected Classic View, follow this
- Double Click on the Folder icon to open it
- Now select the view tab
- Click on Option to Show Hidden Files or Folders
- If you have Selected Control Panel Home View, follow this
- Appearance and Personalization link is to be Clicked
- Select on Show Hidden Files or Folders
- Press Apply Option and then Click on OK.
This will Show all the Folders including those created by HKU\S-1-5-21
Know how to view Hidden Folders on Windows 7, Win 8 and Windows 10
(Following the above steps are necessary to view all the files created by HKU\S-1-5-21 and that is known to exist on Compromised PC.)
- Open the Run Box by holding together the Start Key and R.
- Now Type and input appwiz.cpl and press on OK
- This will take you to the Control Panel, Now Search for Suspicious programs or any entries related to HKU\S-1-5-21. Unistall it once if you happen to find it. However be sure not to Uninstall any other program from the list.
- In the Search Field, Type msconfig and press on Enter, this will pop-up a Window
In the Startup Menu, Uncheck all the HKU\S-1-5-21 related entries or which are Unknown as Manufacturer.
Step 3>> Open the Run Box by Pressing Start Key and R in Combination
- Copy + Paste the following Command as
- notepad %windir%/system32/Drivers/etc/hosts and press on OK
- This will Open a new file. If your system has been hacked by HKU\S-1-5-21, certain IP’s will be displayed which can be found in the bottom of the screen.
Look for the suspicious IP that is present in your Localhost
Step 4>> How to Terminate HKU\S-1-5-21 Running Processes
- Go the Processes Tab by pressing on CTRL+SHIFT+ESC Keys Together.
- Look for the HKU\S-1-5-21 Running Processes.
- Right Click on HKU\S-1-5-21 and End the Process.
Step 5>> How to Remove HKU\S-1-5-21 Related Registry Entries
- Open Registry by Typing Regedit in the Run box and Hit Enter Key
- This will open all the list of entries.
- Now Find and search the entries created by HKU\S-1-5-21 and cautiously delete it.
- Alternatively, you can manually search for it in the list to delete HKU\S-1-5-21 Manually.
Unfortunately, if you are unable to remove HKU\S-1-5-21, Scan your PC Now
Still Couldn’t Remove HKU\S-1-5-21, Watch The Following Video Tutorial
Also submit question and let us know in case you are having some doubt. Our Experts will definitely respond with some positive suggestions for the same. Thanks!