Illsei manual removal:
Kill processes:
el_69.exe, msn.exe, taskmgr.exe
Delete registry values:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell=explorer.exe %Windir%\pchealth\helpctr\binaries\msn.exe
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\NoAdminPage=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDrives=3ffffff
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoRun=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Winoldapp\Disabled=1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify=1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntivirusOverride=1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify=1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntivirusDisableNotify=1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallOverride=1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore\DisableSR=1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\RegisteredOwner=Eliles.B&xAE;
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\RegisteredOrganization=Carpe Diem Leslie.
Delete files:el_69.exe, msn.exe, taskmgr.exe, dos.cmd, smtp.vbe, el_perfecto_69.zip
Misc:The el_perfecto_69.zip file arrives attached to Illsei e-mail messages.
Exact file location:
el_69.exe - C:
dos.cmd - C:\WINDOWS or C:\WINNT
smtp.vbe - C:\WINDOWS\Tasks or C:\WINNT\Tasks
taskmgr.exe - C:\WINDOWS\System32 or C:\WINNT\System32
el_perfecto_69.zip - C:\WINDOWS\Fonts or C:\WINNT\Fonts
msn.exe - C:\WINDOWS\pchealth\helpctr\binaries or C:\WINNT\pchealth\helpctr\binaries
Post Comment: