Satiloler.f manual removal:
Kill processes:
ctfmon.exe, lsass.exe, tml_[X].exe, userinit.exe
Delete registry values:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\system
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs=%System%\init.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SFCDisable=FFFFFF9D
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SFCScan=0
HKEY_CURRENT_USER\Software\ver
HKEY_CURRENT_USER\Software\vs
HKEY_CURRENT_USER\Software\Microsoft\x
Delete files:ctfmon.exe, lsass.exe, tml_[X].exe, userinit.exe, init.dll, sfc.dll, sfc_os.dll, xvid.dll, ip.sys, divx.ini, xvid.ini, bkup.reg
Misc:[X] is a combination of random characters.
Exact file location:
bkup.reg - C:
tml_[X].exe - C:\Windows\Temp or C:\Winnt\Temp
lsass.exe - C:\Program Files\Common Files\System
ip.sys - C:\Windows\System\Drivers, C:\Windows\System32\Drivers or C:\Winnt\System32\Drivers
ctfmon.exe, userinit.exe, init.dll, sfc.dll, sfc_os.dll, xvid.dll, divx.ini, xvid.ini - C:\Windows\System, C:\Windows\System32 or C:\Winnt\System32
Post Comment: