Decoy manual removal:
Kill processes:
dkernel.exe, iexplorer.exe
Delete registry values:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\dkernel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\iexplorer.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell\explorer.exe iexplorer.exe
Delete files:dkernel.exe, iexplorer.exe
Delete directories:C:\Windows\System\I75-D2
C:\Windows\System32\I75-D2
C:\Winnt\System32\I75-D2
Misc:Exact file location:
iexplorer.exe - C:\Windows or C:\Winnt
dkernel.exe - C:\Windows\System\I75-D2, C:\Windows\System32\I75-D2 or C:\Winnt\System32\I75-D2
Post Comment: