Kondeli manual removal:
Kill processes:
klein.exe, winmain.exe, z.exe
Delete registry values:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\winui=C:\z.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell=explorer.exe winmain.exe
Delete files:klein.exe, winmain.exe, z.exe
Misc:The klein.exe file is downloaded by malicious code sent to the vulnerable system. Then this executable is saved as z.exe.
Exact file location:
z.exe - C:
winmain.exe - C:\Windows or C:\Winnt
Post Comment: