Todnab.b manual removal:
Kill processes:
servlog.exe, svhost.exe
Delete registry values:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\SRVState_[X]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Run\system handler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\System=%System%\svhost.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell=explorer.exe %System%\svhost.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit=%System%\userinit.exe,%System%\servlog.exe
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\Load\%System%\servlog.exe
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\AutoRun\echo off|%System%\servlog.exe|cls
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\AutoRun\%System%\svhost.exe /register
Delete files:servlog.exe, svhost.exe
Misc:Todnab.b files can be found in default system directory, which is usually C:\WINDOWS\System32 or C:\WINNT\System32.
Post Comment: