Magflag.b manual removal:
Kill processes:
winldr.exe
Delete registry values:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell=explorer.exe winldr.exe
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List
\%Windir%\explorer.exe=%Windir%\explorer.exe:*:Enabled:explorer
Delete files:winldr.exe
Misc:The winldr.exe file is located in default system directory, which is one of the following: C:\Windows\System, C:\Windows\System32, C:\Winnt\System32.
Downloaded files have random names. They can be found in C:\Windows\Temp or C:\Winnt\Temp folder.
Post Comment: