Browaf manual removal:
Kill processes:
browser.exe, ftpbrowser.exe, msinet.exe, startup.exe, ysnd.exe
Delete registry values:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\IE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\IE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\IE
HKEY_CURRENT_USER\Software\VB and VBA Program Settings\ThePowerGoat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\Local Page=[site address]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\Start Page=[site address]
HKEY_CURRENT_USER\Software\Microsoft\InternetExplorer\Main\Default_Page_URL=[site address]
HKEY_CURRENT_USER\Software\Microsoft\InternetExplorer\Main\HpDed=[site address]
HKEY_CURRENT_USER\Software\Microsoft\InternetExplorer\Main\Local Page=[site address]
HKEY_CURRENT_USER\Software\Microsoft\InternetExplorer\Main\Start Page=[site address]
Delete files:browser.exe, ftpbrowser.exe, msinet.exe, startup.exe, ysnd.exe, sys.dll, msinet.ocx
Misc:[site address] is an address of a web site on the lamanweb.com domain.
Exact file location:
ysnd.exe - C:\YSND
msinet.ocx - C:\Windows\System, C:\Windows\System32 or C:\Winnt\System32
browser.exe, ftpbrowser.exe, msinet.exe, startup.exe, sys.dll - C:\Windows\Temp or C:\Winnt\Temp
Post Comment: