Hotword manual removal:
Kill processes:
explore.exe, [X]svchost.exe
Delete registry values:HKEY_CURRENT_USER\Software\Microsoft\Windows\WU
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\login
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\regedit
Delete files:explore.exe, [X]svchost.exe, login.lnk, mmsystem.dlx, vzzpkghva.crb, windll-objectswin*.dlx
Misc:[X] is a space character.
Files mmsystem.dlx, vzzpkghva.crb and windll-objectswin*.dlx contain recorded keystrokes.
Hotword modifies critical Windows configuration files. Open win.ini and wininit.ini files located in C:\Windows or C:\Winnt folder and delete [WindowsSys] and [WindowsSys32] sections and all the lines in them.
Exact file location:
vzzpkghva.crb - C:\Documents and Settings\[Current User]\Application Data
login.lnk - C:\Documents and Settings\[Current User]\Start Menu\Programs
explore.exe, [X]svchost.exe, mmsystem.dlx, windll-objectswin*.dlx - C:\Windows\System, C:\Windows\System32 or C:\Winnt\System32
Post Comment: