Lsas.Trojan-Spy.DOS.Keycopy manual removal:
Kill processes:
energy.exe hymt.exe tempdoc.exe MD345d.exe
Delete registry values:HKEY_CLASSES_ROOT\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}
HKEY_CLASSES_ROOT\MD345d.DocHostUIHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft
Numerous entries underHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\
Unregister DLLs:FW.dll PE.dll mozcrt19.dll sqlite3.dll
Delete files:cookies.sqlite Instructions.ini Malware Destructor 2009.lnk del.bat ANTIGEN.exe ANTIGEN.sys cb.drv energy.exe energy.tmp FS.sys FS.tmp FW.dll hymt.exe kernel32.drv PE.dll PE.tmp tempdoc.exe tjd.tmp 384.mof MD345d.exe mozcrt19.dll sqlite3.dll vd952342.bd mdestr.cfg IMT7.xml IMT8.xml IMT9.xml
Delete directories:%UserProfile%\Application Data\Malware Destructor 2009
c:\Documents and Settings\All Users\Application Data\345d567
c:\Documents and Settings\All Users\Application Data\345d567\MDestrSys
c:\Documents and Settings\All Users\Application Data\MDestrSys
Post Comment: