Rahack manual removal:
Kill processes:
svchsot.exe, mscolsrv.exe, syshid.exe, srvsxc.exe
Delete registry values:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\sysser
HKEY_LOCAL_MACHINE\SYSTEM\RAdmin
HKEY_LOCAL_MACHINE\SOFTWARE\RAdmin
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSCoolServ
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MSCoolServ
HKEY_CLASSES_ROOT\exefile\shell\open\command\(Default)=syshid.exe %1 %*
HKEY_CLASSES_ROOT\CLSID\[random name]
Delete files:svchsot.exe, mscolsrv.exe, syshid.exe, srvsxc.exe, server.dll, system.vbs
Misc:Exact file location:
svchsot.exe, mscolsrv.exe, syshid.exe, server.dll - C:\Windows\System, C:\Windows\System32 or C:\Winnt\System32
srvsxc.exe - C:\Wutemp
system.vbs - C:\Documents and Settings\[Current User]\Start Menu\Programs\Startup
Post Comment: