Magflag manual removal:
Kill processes:
winldr.exe, rechnung.pdf.exe, flg.exe
Delete registry values:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell=explorer.exe winldr.exe
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\%System%\svchost.exe=
%System%\svchost.exe:*:Enabled:svchost
Delete files:winldr.exe, rechnung.pdf.exe, flg.exe
Misc:The rechnung.pdf.exe file is attached to all Magflag e-mail messages.
The flg.exe file is downloaded from the Internet.
The winldr.exe file can be found in the default system directory, which is one of the following: C:\Windows\System, C:\Windows\System32, C:\Winnt\System32.
Post Comment: