Kiman.b manual removal:
Kill processes:
hdcontroller.exe
Delete registry values:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\hard drive controller
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\hard drive controller
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Start=4
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Start=4
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\wscsvc\Start=4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\EnableDCOM=n
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\EnableRemoteConnect=n
Delete files:hdcontroller.exe, a.bat, 1.reg
Misc:Kiman.b uses TCP ports 135, 139, 443, 445, 1025 and UDP port 1434.
Exact file location:
a.bat - C:
1.reg - C:\Windows\Temp or C:\Winnt\Temp
hdcontroller.exe - C:\Windows\System, C:\Windows\System32 or C:\Winnt\System32
Post Comment: