Pexmor manual removal:
Kill processes:
lsass.exe, msmsgs.exe, svchost.exe, winword.exe
Delete registry values:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\NortonAntivirus=%Windir%\Temp\officehost.vbs
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\OfficeQuickAccess=%Windir%\Temp\officehost.vbs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\NortonAntivirus=%Windir%\Temp\lsass.exe
HKEY_CURRENT_USER\Identities\[VARIABLE NAME]\Software\Microsoft\Outlook Express\5.0\Mail\Compose Use Stationery=1
HKEY_CURRENT_USER\Identities\[VARIABLE NAME]\Software\Microsoft\Outlook Express\5.0\Mail\Stationery Name=%Windir%\Temp\folder.htm
HKEY_CURRENT_USER\Identities\[VARIABLE NAME]\Software\Microsoft\Outlook Express\5.0\Mail\Wide Stationery Name=%Windir%\Temp\folder.htm
HKEY_CURRENT_USER\Software\Microsoft\Office\10.0\Common\MailSettings\NewStationery
Delete files:lsass.exe, msmsgs.exe, svchost.exe, winword.exe, sen.bat, sexo.pif, officehost.vbs, bailando.vbe, desktop.ini, folder.htm
Misc:The infected bailando.vbe file comes attached to each Pexmor e-mail.
Exact file location:
lsass.exe, msmsgs.exe, svchost.exe, winword.exe, officehost.vbs, bailando.vbe, desktop.ini, folder.htm - C:\Windows\Temp or C:\Winnt\Temp
sen.bat, sexo.pif - C:\Windows\Drivers or C:\Winnt\Drivers
Post Comment: