WinLose manual removal:
Kill processes:
allmylifetolive.exe, liveforever.exe, stillalive.exe, welcometosystem.exe
Delete registry values:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\IwillSurvive
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\ThinkDifferent
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ToBeFree
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\crlxss
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WinLogon\Shell explorer.exe C:\stillalive.exe
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\AlternateShell=C:\stillalive.exe
Delete files:allmylifetolive.exe, liveforever.exe, stillalive.exe, welcometosystem.exe, newname.bat, welcometosystem.html
Misc:Exact file location:
stillalive.exe - C:
newname.bat - C:\Windows\Temp or C:\Winnt\Temp
allmylifetolive.exe, liveforever.exe, welcometosystem.exe, welcometosystem.html - C:\Documents and Settings\[Current User]\My Documents
Post Comment: