Lovena manual removal:
Kill processes:
alicia.exe, emira.exe, msconfig.exe, mstry.exe, nova.exe, regedit.exe, startpage.exe, taskmgr.exe, winamp.exe
Delete registry values:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\shell
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\renova
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\renova_c
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\renova_d
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\renova_e
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\renova_f
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\renova_g
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell=explorer.exe [X]\Program Files\Common Files\renova.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit=explorer.exe [X]\Program Files\Common Files\renova.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution\Options\msrun.exe\Debugger=C:\Windows\mstry.exe
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\AlternateShell=C:\Program Files\Common Files\renova.exe
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\AlternateShell=C:\Program Files\Common Files\renova.exe
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\SafeBoot\AlternateShell=C:\Program Files\Common Files\renova.exe
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\SafeBoot\AlternateShell=C:\Program Files\Common Files\renova.exe
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr=1
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System\DisableCMD=0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoControlPanel=0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFind=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFolderOptions=0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoRun=0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSaveSettings=0
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore\DisableConfig=1
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore\DisableSR=1
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Start Page=C:\Renova\renova.htm
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Start Page=C:\Renova\renova.htm
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProductId=Renova
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProductName=Renova
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\RegisteredOrganization=Renova
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\RegisteredOwner=Renova
Delete files:alicia.exe, emira.exe, msconfig.exe, mstry.exe, nova.exe, regedit.exe, startpage.exe, taskmgr.exe, winamp.exe, nova.scr, oldb.tmp, olde.tmp, old10.tmp, renova.htm
Delete directories:C:\Renova
Misc:[X] is one of the following drive letters: C:, D:, E:, F:, G:.
Exact file location:
renova.htm - C:\Renova
mstry.exe, oldb.tmp - C:\Windows
winamp.exe - C:\Program Files\Winamp
taskmgr.exe - C:\Windows\LastGood\System32
alicia.exe, emira.exe, msconfig.exe, nova.exe, regedit.exe, startpage.exe, olde.tmp, old10.tmp - C:\Windows\System32
The nova.scr file arrives attached to Lovena e-mail messages.