Hocgaly manual removal:
Kill processes:
winmem.exe
Delete registry values:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\winmem
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Zone Labs Client
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\winmem
Delete files:winmem.exe, winflag.vxd, winmail.vxd, winpos.vdx, winsrc.vxd
Misc:Hocgaly files can be found in the default system directory, which is one of the following: C:\Windows\System, C:\Windows\System32, C:\Winnt\System32.
Post Comment: