Handy Keylogger manual removal:
Kill processes:
shadow32.exe, svchost.exe, setup.exe, trace.exe
Delete registry values:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WABCOM
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RFC1156Agent
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\svchost
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\svchost
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D8F6A9AF-4F03-88BB-298B-F16260E36C29}
Delete files:shadow32.exe, svchost.exe, setup.exe, trace.exe, register.bat, qutils.dll, hutils.dll, hlib32.dll
Delete directories:C:\Windows\System\XMLEXT
C:\Windows\System32\XMLEXT
C:\Winnt\System32\XMLEXT
Misc:Files shadow32.exe, svchost.exe, qutils.dll, hutils.dll, hlib32.dll can be found in C:\Windows\System, C:\Windows\System32 or C:\Winnt\System32 folders.
Post Comment: