Sedepex manual removal:
Delete registry values:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1768ECFC-4F5C-4F5B-B134-D67294FC78E9}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4368ECFC-4F5C-4F3B-B934-D67494FC78E0}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\SysTray.Exr={4368ECFC-4F5C-4F3B-B934-D67494FC78E0}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\SysTray.Exs={1768ECFC-4F5C-4F5B-B134-D67294FC78E9}
Misc:Sedepex uses files with random names.
The backdoor uses TCP ports 1035 and 1040.
Post Comment: