Lydra manual removal:
Kill processes:
calc.exe, lsassv.exe, msrpc.exe, regedit.exe, winsys.exe
Delete registry values:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\lsassv
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\winsys
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\winsys
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\winsys
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\winsys
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\msrpc
HKEY_CLASSES_ROOT\CLSID\{65D5AFFB-D4EF-49AA-GFFG-5DA5E12E300A}
Delete files:calc.exe, lsassv.exe, msrpc.exe, regedit.exe, winsys.exe, iecomn.dll, pool32.dll, setupiwz.dll, unrar.dll, viaud.dll, rctfd.sys, adobegammaloader.scr
Misc:Exact file location:
adobegammaloader.scr - C:\Documents and Settings\All Users\Start Menu\Programs\Startup
calc.exe, lsassv.exe, msrpc.exe, regedit.exe, winsys.exe, iecomn.dll, pool32.dll, setupiwz.dll, unrar.dll, viaud.dll, rctfd.sys - C:\WINDOWS or C:\WINNT
Post Comment: