Darkmoon manual removal:
Kill processes:
win32.exe, mydll.exe, ___.exe
Delete registry values:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Microsoft=%Windir%\@@@\win32.exe
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\dmserver\Parameters\ServiceDll=%System%\yxgunlzu.d1l
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Yxgunlzu
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_YXGUNLZU
Delete files:win32.exe, mydll.exe, ___.exe, yxgunlzu.sys, yxgunlzu.d1l
Delete directories:C:\Windows\@@@
C:\Winnt\@@@
Misc:Exact file location:
win32.exe, mydll.exe, ___.exe - C:\Windows\@@@ or C:\Winnt\@@@
yxgunlzu.sys - C:\Windows\System\Drivers, C:\Windows\System32\Drivers or C:\Winnt\System32\Drivers
yxgunlzu.d1l - C:\Windows\System, C:\Windows\System32 or C:\Winnt\System32
Post Comment: