polonus
2
Hi Splinterhell,
Here are the manual removal instruction, and the way to evaluate the traces of the malware are gone:
Klone manual removal:
Kill processes:
paradise.raw.exe, symsvcsa.exe, winlogon.exe, .exe
HELP:
Delete registry values:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\nvchost
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\nvchost
Delete files:
paradise.raw.exe, symsvcsa.exe, winlogon.exe, .exe, winuqw32.dll
polonus