NS Keylogger manual removal:
Kill processes:
services.exe, winlogon.exe
Delete registry values:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\SysService=C:\Program Files\NSkeylogger\services.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\NiceRecorderDll.AboutBox
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\NiceRecorderDll.AboutBox.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\NiceRecorderDll.Explorer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\NiceRecorderDll.Explorer.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\NiceRecorderDll.HotkeyControl
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\NiceRecorderDll.HotkeyControl.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\NiceRecorderDll.LoginBox
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\NiceRecorderDll.LoginBox.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\NiceRecorderDll.MailSetting
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\NiceRecorderDll.MailSetting.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\NiceRecorderDll.MonitorControl
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\NiceRecorderDll.MonitorControl.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\NiceRecorderDll.PasswordControl
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\NiceRecorderDll.PasswordControl.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\NiceRecorderDll.RegisterBox
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\NiceRecorderDll.RegisterBox.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\NiceRecorderDll.RegisterTip
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\NiceRecorderDll.RegisterTip.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\NiceRecorderDll.SetPasswordBox
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\NiceRecorderDll.SetPasswordBox.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\NiceRecorderDll.SettingBox
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\NiceRecorderDll.SettingBox.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{252A0AFD-BA48-4CA3-98AD-022B58BD0185}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3D1F63A7-CE32-46EC-8E45-53733227E71B}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{552D3DF3-F32A-459A-8C26-45AD5C1D987C}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{69B1417C-A1EB-4049-86B8-9CBE318E2B1D}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6B8443A7-E6C9-432D-8AD2-43728F696168}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{761EA5D9-5171-432D-99A7-282109373EB8}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{83C02270-7BC9-444E-ADBF-E7AEBA849154}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8B7971F3-4BD8-43A4-A432-5A80DB640BA9}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BDAEB579-3B30-46BF-9BFD-D2F48862BB84}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BF9BCED1-67F2-43DE-8351-16DF6520B7BC}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F4C9FA0B-4E73-41B4-BBBB-B680AB4F9C9D}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{6E9B9701-EDEF-4D00-804C-FD23644C0131}
Delete files:services.exe, winlogon.exe, keylogger.dll, messenger.dll, appdata.dll, gdiplus.dll, configs.ini
Delete directories:C:\Program Files\NSkeylogger
Post Comment: