Popper manual removal:
Kill processes:
offun.exe
Delete registry values:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\[random name]=%Windir%\[random filename].exe
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Windows Overlay Components
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Windows Overlay Components
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OvMon
Delete files:offun.exe
Misc:The trojan uses randomly named files.
All Popper files can be found in main system directory C:\Windows or C:\Winnt.
Post Comment: