Dagonit manual removal:
Kill processes:
dalia2.exe, winspool.exe, wpap.exe
Delete files:dalia2.exe, winspool.exe, wpap.exe, system.bat, dali.reg
Misc:Disable and delete the user account called Service.
Dagonit modifies the values of the following registry entries to:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lanmanserver\Start=2
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RDSessMgr\Start=2
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TermService\Start=2
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr\Start=2
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\fDenyTSConnections=0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\idleWinStationPoolCount=1
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\TSAdvertise=1
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\TSAppCompat=1
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\TSEnabled=1
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\TSUserEnabled=1
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\Licensing Core\EnableConcurrentSessions=0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\Licensing Core\WinStations\RDP-Tcp\fEnableWinStation=1
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\Licensing Core\WinStations\RDP-Tcp\MaxInstanceCount=1
All Dagonit files can be found in the default system directory, which is one of the following: C:\Windows\System, C:\Windows\System32 or C:\Winnt\System32.
Post Comment: