Renama manual removal:
Kill processes:
easy.windows.monitoring.exe, ersvc.exe, mcafee.update.exe.exe, mmsg.exe, safemode.exe, svchost.exe, system.update.exe, [X1].exe
Delete registry values:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Easy.Windows.Monitor
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\mcAfee.Instan.Update
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mmsg
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\system.update
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ERSvc
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srservice\ImagePath=%Windir%\System\svchost.exe
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr=1
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System\DisableCMD=1
Delete files:easy.windows.monitoring.exe, ersvc.exe, mcafee.update.exe.exe, mmsg.exe, safemode.exe, svchost.exe, system.update.exe, [X1].exe, registry1.dll, registry2.dll, [X2].zip
Delete directories:C:\Windows\mmsg
C:\Winnt\mmsg
Misc:[X1] is a name of the file related to a certain application that runs on Windows startup.
[X2] is a random filename.
The file [X2].zip arrives attached to Renama e-mail messages.
Exact file location:
svchost.exe - C:\Windows\System or C:\Winnt\System
mcafee.update.exe.exe, mmsg.exe - C:\Windows\mmsg or C:\Winnt\mmsg
safemode.exe, registry1.dll, registry2.dll - C:\Windows or C:\Winnt
ersvc.exe - C:\Windows\System, C:\Windows\System32 or C:\Winnt\System32
easy.windows.monitoring.exe, system.update.exe - C:\Windows\Config or C:\Winnt\Config
Post Comment: