Adlogix manual removal:
Kill processes:
adstartup.exe, adupdater.exe, guarnset.exe
Delete registry values:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\adstartup
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\guarnset
HKEY_CLASSES_ROOT\Bho8.adlog
HKEY_CLASSES_ROOT\Bho8.adlog.1
HKEY_CLASSES_ROOT\IEEnhancer.IEEhncrObj
HKEY_CLASSES_ROOT\CLSID\{0B90AA1B-F649-44C3-9FD3-736C332CBBCF}
HKEY_CLASSES_ROOT\CLSID\{22B9A67D-E689-44B6-B775-0E8FE84B4F9B}
HKEY_CLASSES_ROOT\Interface\{1CFB8B32-4053-4144-AF6F-1540EEC7F101}
HKEY_CLASSES_ROOT\Interface\{21194DBC-E80C-4B83-8C82-74CBF52C8AAD}
HKEY_CLASSES_ROOT\TypeLib\{E2C6E243-5F01-4031-9218-6178426985B1}
HKEY_LOCAL_MACHINE\SOFTWARE\y036
HKEY_LOCAL_MACHINE\SOFTWARE\Adlogix
HKEY_LOCAL_MACHINE\SOFTWARE\ODBC\PPS
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Blue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0B90AA1B-F649-44C3-9FD3-736C332CBBCF}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{22B9A67D-E689-44B6-B775-0E8FE84B4F9B}
Delete files:adstartup.exe, adupdater.exe, guarnset.exe, ieenhancer.dll, pacifisy.dll
Misc:The threat uses randomly named registry keys and files.
All Adlogix files can be found in the default system directory, which is one of the following: C:\Windows\System, C:\Windows\System32 or C:\Winnt\System32.
Post Comment: