Bakain manual removal:
Kill processes:
about linda.exe, lexplorer.exe, pcguard.exe, script.exe, service5.exe, systroy.exe, welcome.exe
Delete registry values:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\http
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\java
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\serve user
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\service
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\usbtray
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Run\system checker
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell=explorer.exe %System%\tkz16fk\service5.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\System=%System%\tkz16fk\service5.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit=%System%\userinit.exe,%Windir%\pchealth\pcguard.exe
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\load=%System%\tkz16fk\service5.exe
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\Autorun=echo off|%Windir%\pchealth\pcguard.exe|cls
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFind=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoRun=1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SystemFileProtection\ShowPopups=0
Delete files:about linda.exe, lexplorer.exe, pcguard.exe, script.exe, service5.exe, systroy.exe, welcome.exe
Delete directories:C:\WINDOWS\System32\tkz16fk
C:\WINNT\System32\tkz16fk
Misc:Exact file location:
lexplorer.exe - C:\WINDOWS or C:\WINNT
systroy.exe - C:\WINDOWS\inf or C:\WINNT\inf
script.exe - C:\WINDOWS\System32 or C:\WINNT\System32
pcguard.exe - C:\WINDOWS\pchealth or C:\WINNT\pchealth
service5.exe - C:\WINDOWS or C:\WINNT; C:\WINDOWS\System32\tkz16fk or C:\WINNT\System32\tkz16fk
welcome.exe - C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Post Comment: