Pahatia manual removal:
Kill processes:
aku bisa tanpamu.exe, aku kecewa.exe, data [X1].exe, dibalas dengan segalanya.exe, hkcmd.exe, isass.exe, lnetinfo.exe, mr.abram\'s.exe, my documents.exe, patah_0[X2].exe, sejauh mungkin.exe, system.exe, tak seperti dulu.exe, temp.exe, viva elektro.exe, [X3].exe
Delete registry values:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\HotKeysCmd
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\patah hati
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\user logon
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell=explorer.exe C:\Program Files\Microsoft Office\temp.exe
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableCMD=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr=1
HKEY_CURRENT_USER\Software\Policies\Microsoft\CurrentVersion\Policies\Explorer\NoFind=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFolderOptions=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoRun=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Hidden=2
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideFileExt=1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\RegisteredOrganization=mr.abram's
Delete files:aku bisa tanpamu.exe, aku kecewa.exe, data [X1].exe, dibalas dengan segalanya.exe, hkcmd.exe, isass.exe, lnetinfo.exe, mr.abram\'s.exe, my documents.exe, patah_0[X2].exe, sejauh mungkin.exe, system.exe, tak seperti dulu.exe, temp.exe, viva elektro.exe, [X3].exe, krnl32.bat, system startup.pif, Dibalas Dengan Dusta.exe, Kau Pikir Kaulah Segalanya.exe, Patah_0150.exe, My Music.exe, My Pictures.exe, user logon.exe
Misc:[X1] is a name of the compromised computer.
[X2] is a random character.
[X3] is a name of a certain local folder.
Exact file location:
krnl32.bat - C:\Windows\Security
patah_0[X2].exe - C:\Windows\System32
temp.exe - C:\Program Files\Microsoft Office
hkcmd.exe, isass.exe, system.exe - C:\Windows
[X3].exe - C:\Documents and Settings\[Current User]\My Documents
system startup.pif - C:\Documents and Settings\All Users\Start Menu\Programs\Startup
data [X1].exe - C:\Documents and Settings\[Current User]\My Documents, D:, E:, F:, G:, H:, I:, J:, K:, L:, M:, N:, Z:
my documents.exe - C:\Documents and Settings\All Users\Desktop and C:\Documents and Settings\All Users\Start Menu\Programs
aku bisa tanpamu.exe, aku kecewa.exe, dibalas dengan segalanya.exe, lnetinfo.exe, mr.abram's.exe, sejauh mungkin.exe, tak seperti dulu.exe, viva elektro.exe - C:\Windows\System
Post Comment: