Yahmali manual removal:
Kill processes:
csrss.exe, lsass.exe, services.exe, smss.exe, winlogon.exe
Delete registry values:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell=explorer.exe C:\Documents and Settings\[Current User]\Local Settings\Temp\csrss.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell=explorer.exe C:\Documents and Settings\[Current User]\Local Settings\Temp\lsass.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell=explorer.exe C:\Documents and Settings\[Current User]\Local Settings\Temp\services.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell=explorer.exe C:\Documents and Settings\[Current User]\Local Settings\Temp\smss.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell=explorer.exe C:\Documents and Settings\[Current User]\Local Settings\Temp\winlogon.exe
Delete files:csrss.exe, lsass.exe, services.exe, smss.exe, winlogon.exe
Misc:Yahmali files can be found in the folder C:\Documents and Settings\[Current User]\Local Settings\Temp.
Post Comment: