Suclove manual removal:
Kill processes:
loveletter.doc.exe, winlogon.exe
Delete registry values:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\DLL32=dllhost.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\@=C:\winlogon.exe
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools=1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\Shell\Open\Command\@="%System%\loader32.com" %1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\dllfile\Shell\Open\Command\@="1" %*
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFolderOptions=1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\HideFileExt\CheckedValue=1
Delete files:loveletter.doc.exe, winlogon.exe, loader32.com, dllhost.dll, outlook.vbs, sender.vbs
Misc:loveletter.doc.exe is an infected file that arrives attached to Suclove e-mail messages.
Exact file location:
loveletter.doc.exe - C:\Windows or C:\Winnt
winlogon.exe - C:
loader32.com, dllhost.dll - C:\Windows\System, C:\Windows\System32 or C:\Winnt\System32
sender.vbs - C:\Program Files\Yahoo!\Messenger\Profiles
Post Comment: