Dedmir manual removal:
Kill processes:
wincab.exe, winload.exe
Delete registry values:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\win32usr
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\windows update
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Start=4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\EnableDCOM=n
Delete files:wincab.exe, winload.exe
Misc:Exact file location:
winload.exe - C:\WINDOWS or C:\WINNT
wincab.exe - C:\WINDOWS\System32 or C:\WINNT\System32
Post Comment: