Secefa manual removal:
Kill processes:
dodrrr.exe, msdef.exe, mstempf.exe, services.exe, ws3lib.exe, ftp.scr
Delete registry values:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\rpcser32g
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\rpcser32g
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\DisableRegistryTools=0x0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\DisableRegistryTools=0x0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Start=4
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\Enable Firewall=0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\Enable Firewall=0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\Enable Firewall=0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\\Enable Firewall=0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\Enable Firewall=0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\\Enable Firewall=0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\\Enable Firewall=0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\Enable Firewall=0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\Enable Firewall=0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\services.exe=services.exe:*:enabled:services.exe
Delete files:dodrrr.exe, msdef.exe, mstempf.exe, services.exe, ws3lib.exe, qwe.bat, ftp.scr
Misc:Exact file location:
dodrrr.exe, mstempf.exe - C:\Windows or C:\Winnt
msdef.exe, services.exe, ws3lib.exe, qwe.bat, ftp.scr - C:\Windows\System, C:\Windows\System32 or C:\Winnt\System32
Post Comment: