Lahey manual removal:
Delete registry values:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\sb
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr=1
HKEY_CURRENT_USER\Software\Microsoft\Office\9.0\Word\Security\Level=1
HKEY_CURRENT_USER\Software\Microsoft\Office\10.0\Word\Security\Level=1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\NoDesktop=5
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoCloseKey=5
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFind=5
HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Restrictions\NoFileOpen=1
HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Restrictions\NoPrinting=1
Delete files:rolin.bat, bt2.doc, ec9.doc, erc4.doc, fz5.doc, musical.doc, nd1.doc
Delete directories:C:\Arquiv~1
Misc:Exact file location:
rolin.bat - C:\Arquiv~1
musical.doc - C:\Windows\System, C:\Windows\System32 or C:\Winnt\System32
Other virus files reside in several folders with the following names: Bvhl, Dpc, Smlp, Tmrh, Vhp.
Post Comment: