Litmus manual removal:
Kill processes:
blah.exe, erm.exe, image32.exe, mgdoll.exe, mm.exe, msgsrv16.exe, svchost.exe, winsys.exe
Delete registry values:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\LTM2
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\WIN2
Delete files:blah.exe, erm.exe, image32.exe, mgdoll.exe, mm.exe, msgsrv16.exe, svchost.exe, winsys.exe
Delete directories:C:\Windows\Appsvc
C:\Winnt\Appsvc
C:\Windows\img32b
C:\Winnt\img32b
C:\Windows\Litmus
C:\Winnt\Litmus
C:\Windows\Random
C:\Winnt\Random
C:\Windows\Winsys
C:\Winnt\Winsys
Misc:Exact file location:
blah.exe - C:\Windows\VxD or C:\Winnt\VxD
erm.exe, mm.exe, mgdoll.exe msgsrv16.exe - C:\Windows\Litmus or C:\Winnt\Litmus
image32.exe - C:\Windows\img32b or C:\Winnt\img32b
svchost.exe - C:\Windows\Random, C:\Winnt\Random or C:\Windows\Appsvc, C:\Winnt\Appsvc
winsys.exe - C:\Windows\Winsys or C:\Winnt\Winsys
Post Comment: