Fgbot manual removal:
Kill processes:
rufg.exe, upfg.exe
Delete registry values:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\[X]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\fgsrv
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\fgrunfrom
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\fgcomment
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\fgid
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\fgnoinstall
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\fgversion
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\sizeofformlogfile
HKEY_CLASSES_ROOT\CLSID\[random name]
Delete files:rufg.exe, upfg.exe, dotcfg.dll, fsrv.dll, fgsrv2.dll, phffg.dll, ulffg.dll
Misc:[X] is a space character.
All Fgbot files can be found in default system directory, which is one of the following: C:\Windows\System, C:\Windows\System32, C:\Winnt\System32.
Post Comment: