Ryknos manual removal:
Kill processes:
$sys$drv.exe, bk.exe
Delete registry values:HKEY_CURRENT_USER\[long string of random characters]\$sys$drv=$sys$drv.exe
Delete files:$sys$drv.exe, bk.exe
Misc:The threat can infect any system except for those, where First4DRM is already installed from Sony BMG content-protected music CDs.
The bk.exe file installs the Looksky.b backdoor.
The $sys$drv.exe file can be found in default system directory, which is one of the following: C:\Windows\System, C:\Windows\System32, C:\Winnt\System32.
Post Comment: