Ryknos.b manual removal:
Kill processes:
$sys$xp.exe
Delete registry values:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\$sys$cmp=$sys$xp.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\$sys$cmp=$sys$xp.exe
Delete files:$sys$xp.exe
Misc:The threat can infect any system except for those, where First4DRM is already installed from Sony BMG content-protected music CDs.
The $sys$xp.exe file can be found in default system directory, which is one of the following: C:\Windows\System, C:\Windows\System32, C:\Winnt\System32.
Post Comment: