Mixpel manual removal:
Kill processes:
iepv_msw.exe, msw_n.exe, rundll32.exe
Delete registry values:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\MSHelper
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\MSRemote
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\UrlMon
HKEY_CLASSES_ROOT\CLSID\{17916831-3440-4891-6077-177038848182}
HKEY_CLASSES_ROOT\CLSID\{78839981-6447-1922-7868-541346117994}
HKEY_CLASSES_ROOT\CLSID\{78839981-6447-1922-7868-541346117995}
Unregister DLLs:msremote.dll, msw_a.dll, msw_h.dll, msw_k.dll, msw_p.dll, ms[X].dll
Delete files:iepv_msw.exe, msw_n.exe, rundll32.exe, msremote.dll, msw_a.dll, msw_h.dll, msw_k.dll, msw_p.dll, ms[X].dll, flash postcard.zip, greeting card.zip, postcard.zip, dload.ini
Misc:[X] is a combination of 5 random letters.
Files postcard.zip, greeting card.zip and postcard.zip arrive attached to bogus e-mail messages.
Exact file location:
iepv_msw.exe, ms[X].dll, dload.ini - C:\WINDOWS\System32 or C:\WINNT\System32
msw_n.exe, rundll32.exe, msremote.dll, msw_a.dll, msw_h.dll, msw_k.dll, msw_p.dll - C:\WINDOWS\Help or C:\WINNT\Help
Post Comment: