Peerload manual removal:
Kill processes:
winlogin.exe
Delete registry values:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\winlogin=%System%\winlogin.exe
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Bar=[site address]
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Page=[site address]
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Start Page=[site address]
Delete files:winlogin.exe
Misc:[site address] is an adress of a web site on the p2p-load.de domain.
The parasite uses files with different names.
The winlogin.exe file can be found in the default system directory, which is one of the following: C:\Windows\System, C:\Windows\System32, C:\Winnt\System32.
Post Comment: