Ritdoor.b manual removal:
Kill processes:
msdeff.exe, mstempf.exe, winlogon.exe
Delete registry values:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\rpcserv32g
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\iepfsgdc=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\DisableRegistryTools=0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\DisableRegistryTools=0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Start=4
Delete files:msdeff.exe, mstempf.exe, winlogon.exe
Misc:Ritdoor.b files can be found in C:\Windows or C:\Winnt folder.
Post Comment: