ActMon manual removal:
Kill processes:
acmcc.exe, srvprc.exe, wskrnl.exe, wskrnlb.exe
Delete registry values:HKEY_LOCAL_MACHINE\SOFTWARE\srvprc
HKEY_LOCAL_MACHINE\SOFTWARE\wskrnl
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\srvprc
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\wskrnl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\wskrnlc
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wskrnlc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96B-E325-11CE-BFC1-08002BE10318}
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E96B-E325-11CE-BFC1-08002BE10318}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0303\4&5289e18&0\Control\ActiveService=wskrnlc
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\ACPI\PNP0303\4&5289e18&0\Control\ActiveService=wskrnlc
Delete files:acmcc.exe, srvprc.exe, wskrnl.exe, wskrnlb.exe, rbwinx1.dll, wskrnlc.dll, wskrnld.dll, wskrnle.dll, wskrnlc.sys
Delete directories:C:\Documents and Settings\[Current User]\Application Data\syswin
Misc:Exact file location:
wskrnlc.sys - C:\Windows\System\Drivers, C:\Windows\System32\Drivers or C:\Winnt\System32\Drivers
other files - C:\Windows\System, C:\Windows\System32 or C:\Winnt\System32
Post Comment: