iGetNet manual removal:
Kill processes:
winstart001.exe, nlnp13.exe
Delete registry values:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\winstart001.exe=%system%\Winstart001.exe ?€“boot
HKEY_CLASSES_ROOT\CLSID\{60E78CAC-E9A7-4302-B9EE-8582EDE22FBF}
HKEY_CLASSES_ROOT\Interface\{18333387-5082-4710-94DF-9600CF6B2D5B}
HKEY_CLASSES_ROOT\Interface\{3c8cde30-d013-4093-b00e-adbc74f33315}
HKEY_CLASSES_ROOT\Interface\{676058E3-89BD-11D6-8A8C-0050BA8452C0}
HKEY_CLASSES_ROOT\Interface\{F94C0089-9394-4E44-B4EA-58DBA1F7B84E}
HKEY_CLASSES_ROOT\TypeLib\{676058DB-89BD-11D6-8A8C-0050BA8452C0}
HKEY_CLASSES_ROOT\TypeLib\{974CC25E-D62C-4278-84E6-A806726E37BC}
HKEY_CLASSES_ROOT\TypeLib\{ACBA087F-1547-41DE-8E9E-3F0963CE4BEF}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Rsp.BizLgk
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BHO.clsDockWindow
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BHO.clslnetSpeak
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BHO.clsUrlSearch
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{676058E4-89BD-11D6-8A8C-0050BA8452C0}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{730F2451-A3FE-4A72-938C-FC8A74F15978}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D5DE8D20-5BB8-11D1-A1E3-00A0C90F2731}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{730F2451-A3FE-4A72-938C-FC8A74F15978
Delete files:winstart001.exe, nlnp13.exe, rsp001.dll, bho001.dll, update_com.dll
Why is the government not concerned with this clear and present danger?
I am so angry at this malware makes that abuse my right to not be infected with this virus.
http://www.bleepingcomputer.com/files/killbox.php
Post Comment: