Syginre manual removal:
Kill processes:
adobe global hack.exe, aim triton6.0.exe, alg.exe, aluscheduler.exe, cachemanxp.exe, calculator.exe, ccapp.exe, ccproxy.exe, csrss.exe, dllhost.exe, floppy options.exe, important information.exe, kdb34894234.exe, limewirepro.exe, lsass.exe, minesweeper.exe, motivebrowser.exe, msdtc.exe, myspace password cracker.exe, nopde.exe, nprotect.exe, rundll32.exe, services32.exe, smss.exe, spoolsv.exe, svchost.exe, system.exe, system idle process.exe, readme.exe, taskmanager.exe, virus scanner.exe, winlogon.exe, win32dll.exe, zlclient.exe, 123 copy dvd.exe
Delete registry values:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\csrss
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\nprotect
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\spoolsv
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\syscheck
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\system idle process
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\winlogon
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\aluscheduler
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\nav
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\smss
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\svchost
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\windows update
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\win services
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\zlclient
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\zone labs client
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices\services
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisableRegistryTools=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\HideClock=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoAddPrinter=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoClose=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoCommonGroups=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDesktop=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDrives=0x1B39
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFind=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoNetworkConnections=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoRun=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSaveSettings=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetFolders=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetTaskbar=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSMHelp=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSMMyDocs=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\RestrictRun=1
HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Restrictions\NoBrowserClose=1
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\RestrictAnonymous=1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\EnableDCOM=n
HKEY_CURRENT_USER\Control Panel\Keyboard\KeyboardDelay=9
HKEY_CURRENT_USER\Control Panel\Mouse\MouseSpeed=0
Delete files:adobe global hack.exe, aim triton6.0.exe, alg.exe, aluscheduler.exe, cachemanxp.exe, calculator.exe, ccapp.exe, ccproxy.exe, csrss.exe, dllhost.exe, floppy options.exe, important information.exe, kdb34894234.exe, limewirepro.exe, lsass.exe, minesweeper.exe, motivebrowser.exe, msdtc.exe, myspace password cracker.exe, nopde.exe, nprotect.exe, rundll32.exe, services32.exe, smss.exe, spoolsv.exe, svchost.exe, system.exe, system idle process.exe, readme.exe, taskmanager.exe, virus scanner.exe, winlogon.exe, win32dll.exe, zlclient.exe, 123 copy dvd.exe
Misc:Exact file location:
floppy options - A:
calculator.exe - C:
aim triton6.0.exe - C:\Program Files
win32dll.exe - C:\WINDOWS\System32 or C:\WINNT\System32
limewirepro.exe - C:\Program Files\LimeWire\.NetworkShare
123 copy dvd.exe - C:\Documents and Settings\All Users\Desktop
adobe global hack.exe - C:\Documents and Settings\[Current User]\Shared
kdb34894234.exe, minesweeper.exe, services32.exe - C:\WINDOWS or C:\WINNT
important information.exe, readme.exe - C:\Documents and Settings\All Users\Start Menu
myspace password cracker.exe - C:\Documents and Settings\All Users\Shared Documents
service host.exe, virus scanner.exe - C:\Documents and Settings\All Users\Start Menu\Programs
alg.exe, aluscheduler.exe, cachemanxp.exe, ccapp.exe, ccproxy.exe, csrss.exe, dllhost.exe, lsass.exe, motivebrowser.exe, msdtc.exe, nopde.exe, nprotect.exe, rundll32.exe, smss.exe, spoolsv.exe, svchost.exe, system.exe,system idle process.exe, taskmanager.exe, winlogon.exe, zlclient.exe - the root of local hard drive (usually, C:)
Post Comment: