Loxbot.b manual removal:
Kill processes:
express.exe
Delete registry values:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Outlook Mail Service=express.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Outlook Mail Service=express.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\Outlook Mail Service=express.exe
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\EnableFirewall=0
Delete files:express.exe
Misc:The express.exe file is located in default system directory, which is one of the following: C:\Windows\System, C:\Windows\System32, C:\Winnt\System32.
Loxbot.b uses 9515 TCP port.
Post Comment: