Puregirls manual removal:
Kill processes:
aclservice.exe
Delete registry values:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AclService
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AclService
HKEY_CLASSES_ROOT\ACL.AclCtrl.1
HKEY_CLASSES_ROOT\AppID\aclservice.exe
HKEY_CLASSES_ROOT\AppID\{ADF47FB7-7FE7-4229-BA1F-19C6B7D936A1}
HKEY_CLASSES_ROOT\CLSID\{1B4066DD-C7E6-426D-BDD5-458954FE51FF}
HKEY_CLASSES_ROOT\CLSID\{A12A4BD2-9A1E-4536-A9C7-202A7F13ADCC}
HKEY_CLASSES_ROOT\Interface\{1D7BA44B-FBB4-4D6F-BC74-0917DAD0C605}
HKEY_CLASSES_ROOT\Interface\{65E32B18-9689-4D58-B891-56E7CE65C6C0}
HKEY_CLASSES_ROOT\TypeLib\{049FD307-FB79-489F-8AB4-4FC73A1F59B5}
HKEY_CLASSES_ROOT\TypeLib\{4FE80730-2A8B-4E96-BF40-D73FE8DAF980}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\%System%/aclservice.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\%System%/acl.ocx
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\%System%/acl.bmp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1B4066DD-C7E6-426D-BDD5-458954FE51FF}
HKEY_LOCAL_MACHINE\SOFTWARE\puregirls.tv
Delete files:aclservice.exe, acl.ocx, acl.bmp
Misc:The trojan is related to the www.puregirls.tv web site.
Most Puregirls files can be found in default system directory, which is C:\Windows\System32 or C:\Winnt\System32.
Post Comment: