Feebs manual removal:
Kill processes:
command.exe, ms[X].exe, ms[X]32.exe, web.exe, websetup.exe
Delete registry values:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\ms[X]
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\EnableFirewall=0
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile\EnableFirewall=0
HKEY_CURRENT_USER\Software\Policies\Microsoft\WindowsFirewall\DomainProfile\EnableFirewall=0
HKEY_CURRENT_USER\Software\Policies\Microsoft\WindowsFirewall\StandardProfile\EnableFirewall=0
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\web=[site address]
Delete files:command.exe, ms[X].exe, ms[X]32.exe, web.exe, websetup.exe
Misc:[X] is a set of random characters.
[site address] is an address of a web site on the popcapfree.t35.com domain.
Exact file location:
command.exe, web.exe - C:
ms[X].exe, ms[X]32.exe - C:\Windows\System, C:\Windows\System32 or C:\Winnt\System32
websetup.exe - inside Zip archives that the worm distributes through file sharing networks
Post Comment: