What is Lecivio as well as dismissal instructions
Lecivio is the worm which spreads by removable media as well as mapped network drives. The bug downloads from the Internet as well as executes antagonistic files. It runs as the use upon each Windows startup.
Lecivio primer removal:
Kill processes:
cmdial.exe, dnandlk.exe, goku.exe, inf.exe, rpcss.exe, userinit.exe, viollice.exe
Delete registry values:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\dpnmodempl
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\HTTPFilter
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\HTTPSSL
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rpcss
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit=%System%\userinit.exe,%System%\cmdial.exe,%System%\viollice.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\rpcss.exe
Delete files:
cmdial.exe, dnandlk.exe, goku.exe, inf.exe, rpcss.exe, userinit.exe, viollice.exe, dpnmodempl.dll
Misc:
Exact record location:
goku.exe – C:
inf.exe – C:\WINDOWS\System32 or C:\WINNT\System32; removable media as well as mapped network drives
cmdial.exe, dnandlk.exe, rpcss.exe, userinit.exe, viollice.exe, dpnmodempl.dll – C:\WINDOWS\System32 or C:\WINNT\System32