Dermon manual removal:
Kill processes:
winserver.exe
Delete registry values:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\win32 system server=%System%\winserver.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\win32 system server=%System%\winserver.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices\win32 system server=%System%\winserver.exe
Delete files:winserver.exe, winserv.dll, winserv32.dll, winserv.ini, winserv.dat
Misc:All Dermon files can be found in the default system directory. Depending on your Windows version, it can be C:\Windows\System, C:\Windows\System32 or C:\Winnt\System32. File winserv.dat contains recorded keystrokes.
Post Comment: