Monikey manual removal:
Kill processes:
chkdskw.exe, mstcpmon.exe, sfc32.exe
Delete registry values:HKEY_CLASSES_ROOT\CLSID\[random numer]\InProcServer32\(Default)=mswshell.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs=karnal32.dll
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Shell=[random number]
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Applets\SysBackup
Delete files:chkdskw.exe, mstcpmon.exe, sfc32.exe, itstore.dll, karnal32.dll, mslogon.dll, mswshell.dll
Misc:The parasite modifies critical Windows configuration file win.ini located in C:\Windows or C:\Winnt folder. Open this file and delete the [chkdsk] section and all the lines it contains.
All Monikey files can be found in default system directory, which is one of the following: C:\Windows\System, C:\Windows\System32, C:\Winnt\System32.
Post Comment: