Mobler manual removal:
Kill processes:
rahasia [X].exe, svchost.exe, system.exe, windows.exe, [X] adult photos & videos.exe, [X] gambar masa kecil.exe, [X] mau tau aja.exe, [X] mp3 collection.exe, [X] photos data.exe, [X] secret data.exe
Delete registry values:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\windows
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\windows
HKEY_CLASSES_ROOT\batfile\Shell\Edit\Command\Default=%Windir%\svchost.exe
HKEY_CLASSES_ROOT\batfile\Shell\Open\Command\Default=%Windir%\svchost.exe
HKEY_CLASSES_ROOT\chm.file\Shell\Open\Command\Default=%Windir%\svchost.exe
HKEY_CLASSES_ROOT\cmdfile\Shell\Edit\Command\Default=%Windir%\svchost.exe
HKEY_CLASSES_ROOT\cmdfile\Shell\Open\Command\Default=%Windir%\svchost.exe
HKEY_CLASSES_ROOT\comfile\Shell\Open\Command\Default=%Windir%\svchost.exe
HKEY_CLASSES_ROOT\htmlfile\Shell\Open\Command\Default=%Windir%\svchost.exe
HKEY_CLASSES_ROOT\inffile\Shell\Open\Command\Default=%Windir%\svchost.exe
HKEY_CLASSES_ROOT\JSFile\Shell\Edit\Command\Default=%Windir%\svchost.exe
HKEY_CLASSES_ROOT\JSFile\Shell\Open\Command\Default=%Windir%\svchost.exe
HKEY_CLASSES_ROOT\MSCFile\Shell\Open\command\Default=%Windir%\svchost.exe
HKEY_CLASSES_ROOT\regfile\Shell\Edit\Command\Default=%Windir%\svchost.exe
HKEY_CLASSES_ROOT\regfile\Shell\Open\Command\Default=%Windir%\svchost.exe
HKEY_CLASSES_ROOT\txtfile\Shell\Open\Command\Default=%Windir%\svchost.exe
HKEY_CLASSES_ROOT\VBSFile\Shell\Edit\Command\Default=%Windir%\svchost.exe
HKEY_CLASSES_ROOT\VBSFile\Shell\Open\Command\Default=%Windir%\svchost.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\attrib.exe\Default=%Windir%\svchost.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\del.exe\Default=%Windir%\svchost.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Dxdiag.exe\Default=%Windir%\svchost.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\reg.exe\Default=%Windir%\svchost.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\regedit.exe\Default=%Windir%\svchost.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\taskkill.exe\Default=%Windir%\svchost.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\HELPCTR.EXE\Default=%Windir%\svchost.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MSCONFIG.EXE\Default=%Windir%\svchost.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MSMSGS.EXE\Default=%Windir%\svchost.exe
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFind=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFolderOptions=1
Delete files:rahasia [X].exe, svchost.exe, system.exe, windows.exe, [X] adult photos & videos.exe, [X] gambar masa kecil.exe, [X] mau tau aja.exe, [X] mp3 collection.exe, [X] photos data.exe, [X] secret data.exe
Misc:[X] is the current user name.
Exact file location:
windows.exe - C:
svchost.exe - C:\Windows or C:\Winnt
system.exe - C:\Windows\System, C:\Windows\System32 or C:\Winnt\System32