Dedmir manual removal:
Kill processes:
wincab.exe, winload.exe
Delete registry values:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\win32usr
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\windows update
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Start=4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\EnableDCOM=n
Delete files:wincab.exe, winload.exe
Misc:Exact file location:
winload.exe - C:\WINDOWS or C:\WINNT
wincab.exe - C:\WINDOWS\System32 or C:\WINNT\System32
Post Comment:
Attention: Use this form only if you have additional information about Dedmir parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.