Lazar manual removal:
Kill processes:
indexindicator.exe, memreload.exe, recalculate.exe, reload.exe, suiteoffices.exe
Delete registry values:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\diesel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\indexindicator
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\memreload
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\suite
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\reload
Delete files:indexindicator.exe, memreload.exe, recalculate.exe, reload.exe, suiteoffices.exe
Misc:The parasite modifies critical Windows configuration file win.ini located in C:\Windows or C:\Winnt folder. Open this file and delete the following lines:
[{LAZ00000-1111-1111-1111-111111111111}]
lastday=[date]
dayview=[number]
daynumber=[number]
Exact file location:
memreload.exe, reload.exe - C:\Program Files\ServicePackFiles
indexindicator.exe, recalculate.exe, suiteoffices.exe - C:\Windows\System, C:\Windows\System32 or C:\Winnt\System32
Post Comment: