Clagger manual removal:
Kill processes:
ebay_rechnung.pdf.exe, ipf.exe
Delete registry values:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\IPF
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsShell
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\
%System%\ipf.exe=%System%\ipf.exe:*:Enabled:ipf
Delete files:ebay_rechnung.pdf.exe, ipf.exe
Misc:The trojan usually arrives as the ebay_rechnung.pdf.exe file.
The ipf.exe file can be found in the default system directory, which is one of the following: C:\Windows\System, C:\Windows\System32 or C:\Winnt\System32.
Post Comment: