Schoeberl.e manual removal:
Kill processes:
rechnung.pdf.exe, [X1].exe, [X2].exe
Delete registry values:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\winupdate
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\winupdate
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunServices\winupdate
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\winupdate
HKEY_CURRENT_USER\SYSTEM\CurrentControlSet\Control\Lsa\winupdate
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\winupdate
HKEY_CURRENT_USER\Software\Microsoft\OLE\winupdate
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\winupdate
HKEY_CURRENT_USER\Software\ODBC\dwlcounter
Delete files:rechnung.pdf.exe, [X1].exe, [X2].exe, ipv6monl.dll
Misc:[X1] is a random name.
[X2] is a combination of random digits.
The rechnung.pdf.exe file arrives attached to bogus e-mail messages.
Exact file location:
[X2].exe - C:\WINDOWS\Temp or C:\WINNT\Temp
[X1].exe, ipv6monl.dll - C:\WINDOWS\System32 or C:\WINNT\System32
Post Comment: