Ritdoor manual removal:
Kill processes:
msdefr.exe, nb32ext4.exe, services.exe
Delete registry values:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\rpcserv32g
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\helloworld3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit %System%\userinit.exe,%Windows%\services.exe
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\iepsdgxc=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\DisableRegistryTools=0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\DisableRegistryTools=0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Start=4
Delete files:msdefr.exe, nb32ext4.exe, services.exe
Misc:Ritdoor files can be found in C:\Windows or C:\Winnt folder.
Post Comment: