Lunalight manual removal:
Kill processes:
data [X1].exe, foto [X1].exe, l.exe, smss.exe, system.exe, winlogon.exe, 5.exe, [X2].exe
Delete registry values:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\[X2]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\[X2]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\AlternateShell=[X2].exe
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\SafeBoot\AlternateShell=[X2].exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell=explorer.exe, C:\Documents and Settings\[Current User]\Templates\[X2]\[X2].exe
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools=1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msconfig.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedit.exe
HKEY_CURRENT_USER\Software\VB and VBA Program Settings\titta
HKEY_CURRENT_USER\Software\VB and VBA Program Settings\untukmu2
Delete files:data [X1].exe, foto [X1].exe, l.exe, smss.exe, system.exe, winlogon.exe, 5.exe, [X2].exe, crtsys.dll, l.com, adodb.cmd, lsass.exe0.cmd, moonlight.scr
Delete directories:C:\Documents and Settings\[Current User]\Templates\[X2]
Misc:[X1] is the current user name.
[X2] is a combination of random digits.
Exact file location:
adodb.cmd - C:\Documents and Settings\[Current User]\Start Menu\Programs\Startup
crtsys.dll, moonlight.scr - C:\Windows\System, C:\Windows\System32 or C:\Winnt\System32
[X2].exe - C:\Documents and Settings\[Current User]\Templates\[X2]; C:\Windows or C:\Winnt; C:\Windows\System, C:\Windows\System32 or C:\Winnt\System32
Post Comment: