Satiloler.d manual removal:
Kill processes:
ctfmon.exe, lsass.exe, userinit.exe
Delete registry values:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\ctfmon.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\userinit
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\%System%\userinit.exe
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\%Windir%\System\ctfmon.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SFCDisable=FFFFFF9D
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SFCScan=0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\System
HKEY_LOCAL_MACHINE\SOFTWARE\tvr
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\d
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\gold
Delete files:ctfmon.exe, lsass.exe, userinit.exe, divx5.dll, sfc.dll, sfc_os.dll, cmd.txt, hst.txt, h323.txt
Misc:The h323.txt file contains stolen user sensitive information.
Exact file location:
ctfmon.exe - C:\Windows\System or C:\Winnt\System
lsass.exe - C:\Program Files\Common Files\System
userinit.exe, divx5.dll, sfc.dll, sfc_os.dll, cmd.txt, hst.txt, h323.txt - C:\Windows\System, C:\Windows\System32 or C:\Winnt\System32
Post Comment: