Chaim manual removal:
Kill processes:
ntps.exe, spec.exe
Delete registry values:HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\NETAPI
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\EnableFirewall=0
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile\EnableFirewall=0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\EnableDCOM=n
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify=1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusOverride=1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify=1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallOverride=1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify=1
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\DoNotAllowXPSP2=1
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Messenger\Start=4
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\Start=4
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr\Start=4
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wscsvc\Start=4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current Version\Shell Extensions\Melt
Delete files:ntps.exe, spec.exe
Misc:Exact file location:
spec.exe - C:
ntps.exe - C:\Windows\System, C:\Windows\System32 or C:\Winnt\System32
Post Comment: