WinWhatWhere manual removal:
Kill processes:
express.exe, il40.exe, msdfcng.exe, msegcng.exe, updsem.exe, winsutl.exe, xpress.exe
Delete registry values:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WinWhatWhere
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\msdfcng.exe
Delete files:express.exe, il40.exe, msdfcng.exe, msegcng.exe, updsem.exe, winsutl.exe, xpress.exe, _isreg32.dll, winsdoc8.sys, winsdoc16.sys, winsdoc32.sys
Misc:WinWhatWhere files can be found in C:\Windows\System\OLBE, C:\Windows\System32\OLBE or C:\Winnt\System32\OLBE directory.
Puts files all over the place. Uses the registry as a garbage dump.
Installs a whole lot of VB runtime modules and components to the victim machine.
Post Comment: