Piggi manual removal:
Kill processes:
lsass.exe, svchost.exe
Delete registry values:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\[filename]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell=explorer.exe %Windir%\lsass.exe
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\msfsr
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\[X]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\[filename]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Start=3
Delete files:lsass.exe, svchost.exe, msfsr.sys, [X].sys
Misc:[X] is a combination of 5 random characters.
Exact file location:
lsass.exe - C:\WINDOWS or C:\WINNT
msfsr.sys - C:\WINDOWS\System32 or C:\WINNT\System32
[X].sys - C:\WINDOWS\System32\drivers or C:\WINNT\System32\drivers
svchost.exe - C:\WINDOWS or C:\WINNT; C:\WINDOWS\System32\dllcache or C:\WINNT\System32\dllcache
Some files might be hidden by the rootkit.
Post Comment: