Zalon.b manual removal:
Kill processes:
mdmex2.exe
Delete registry values:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\svcmanager
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\%System%\mdmex2.exe
HKEY_CURRENT_USER\Software\Microsoft\CryptoSecure
Delete files:mdmex2.exe
Misc:The mdmex2.exe file usually resides in default system directory, which can be C:\WINDOWS\System32 or C:\WINNT\System32.
Post Comment: