Gallory manual removal:
Kill processes:
cd_key.exe, mstask32.exe, sysbackup.exe, finderall.bat
Delete registry values:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\sysbackup
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell=explorer.exe %System%\mstask32.exe
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskmgr=1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Sensor\Redkey
Delete files:cd_key.exe, mstask32.exe, sysbackup.exe, finderall.bat
Misc:Gallory can create more files with various names.
Exact file location:
sysbackup.exe, finderall.bat - C:\Windows or C:\Winnt
cd_key.exe, mstask32.exe - C:\Windows\System, C:\Windows\System32 or C:\Winnt\System32
Post Comment: