Newrug manual removal:
Kill processes:
nordsys.exe, [X1].exe, [X2].exe
Delete registry values:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\nord
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\nord
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Start=4
Delete files:nordsys.exe, [X1].exe, [X2].exe
Misc:[X1] is a random filename.
[X2] is a combination of random characters.
Files nordsys.exe and [X1].exe can be found in default system directory, which is one of the following: C:\WINDOWS\System32, C:\WINNT\System32.
Post Comment: