Feebs.j manual removal:
Kill processes:
ms[X1].exe, userinit.exe
Delete registry values:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\[filename]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CD5AC91B-AE7B-E83A-0C4C-E616075972F3}
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\mal
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\web
HKEY_CURRENT_USER\Software\Policies\Microsoft\WindowsFirewall\DomainProfile\EnableFirewall=0
HKEY_CURRENT_USER\Software\Policies\Microsoft\WindowsFirewall\StandardProfile\EnableFirewall=0
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\EnableFirewall=0
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile\EnableFirewall=0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS[X4]
Delete files:ms[X1].exe, userinit.exe, ms[X2]32.dll, ms[X3]
Misc:[X1], [X2], [X3] and [X4] are four different strings comprised of random characters.
Filenames may vary. Feebs.j creates randomly named registry keys.
Exact file location:
userinit.exe - C:\Recycled
ms[X1].exe, ms[X2]32.dll, ms[X3] - C:\Windows\System, C:\Windows\System32 or C:\Winnt\System32
Post Comment: