Foamer manual removal:
Kill processes:
explorer.exe, moaphie.exe, svchost.exe, winnt.exe
Delete registry values:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\shell
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\svchost
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\winnt
HKEY_CURRENT_USER\Software\Microsoft\InternetExplorer\Main\Start Page=[site address]
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoRun=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoViewContextMenu=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\Policies\Explorer=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\Policies\System=1
HKEY_LOCAL_MACHINE\SOFTWARE\MoaphieSig
Delete files:explorer.exe, moaphie.exe, svchost.exe, winnt.exe
Misc:[site address] is an address of a web site on the websamba.com domain.
Exact file location:
svchost.exe, winnt.exe - C:\Windows or C:\Winnt
moaphie.exe - the root of mapped network drives
explorer.exe - C:\Windows\System, C:\Windows\System32 or C:\Winnt\System32
Post Comment: