W32.Downadup.C manual removal:
Delete registry values:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\?€?[RANDOM CHARACTERS]?€? = ?€?rundll32.exe ?€?[RANDOM DLL FILE NAME]?€?, [RANDOM PARAMETER STRING]?€?
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\[RANDOM CHARACTERS]\?€?ImagePath?€? = %System%\svchost.exe -k netsvcs
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\[RANDOM CHARACTERS]\Parameters\?€?ServiceDll?€? = ?€?[PATH TO SECURITY RISK]?€?
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\?€?Windows Defender?€?
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\explorer\ShellServiceObjects\{FD6905CE-952F-41F1-9A6F-135D9C6622CC}
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot
Post Comment: