Manual removal of CLASSIFIED:
1. Click START + RUN.
2. Type CMD /D and click OK
3. Sa Command Prompt, type taskkill /im services.exe /im system.exe /im lsass.exe /im nthlpsvc1.exe /im nthlpsvc2.exe /im dirlock.exe /t press ENTER
4. Repeat step 3 as many times and as fast as you can (press nyo lang po ang UP ARROW para automatic na maulit ang command line), hanggang sa ganito na ang lumalabas:
ERROR: The process with PID 3892 child of PID 732 could not be terminated.
Reason: This process can only be terminated forcefully ( with /F option ).
ERROR: The process with PID 732 child of PID 560 could not be terminated.
Reason: One or more child processes of this process were still running.
ERROR: The process with PID 792 child of PID 560 could not be terminated.
Reason: This process can only be terminated forcefully ( with /F option ).
ERROR: The process with PID 860 child of PID 560 could not be terminated.
Reason: This process can only be terminated forcefully ( with /F option ).
ERROR: The process with PID 944 child of PID 560 could not be terminated.
Reason: This process can only be terminated forcefully ( with /F option ).
ERROR: The process with PID 1096 child of PID 560 could not be terminated.
Reason: This process can only be terminated forcefully ( with /F option ).
ERROR: The process with PID 1244 child of PID 560 could not be terminated.
Reason: This process can only be terminated forcefully ( with /F option ).
ERROR: The process with PID 1280 child of PID 560 could not be terminated.
Reason: This process can only be terminated forcefully ( with /F option ).
ERROR: The process with PID 1300 child of PID 560 could not be terminated.
Reason: This process can only be terminated forcefully ( with /F option ).
SUCCESS: The process with PID 1988 child of PID 560 has been terminated.
ERROR: The process with PID 2024 child of PID 560 could not be terminated.
Reason: This process can only be terminated forcefully ( with /F option ).
ERROR: The process with PID 2240 child of PID 560 could not be terminated.
Reason: This process can only be terminated forcefully ( with /F option ).
ERROR: The process with PID 3848 child of PID 560 could not be terminated.
Reason: This process can only be terminated forcefully ( with /F option ).
ERROR: The process with PID 560 child of PID 516 could not be terminated.
Reason: One or more child processes of this process were still running.
ERROR: The process with PID 572 child of PID 516 could not be terminated.
Reason: This process can only be terminated forcefully ( with /F option ).
ERROR: The process "system.exe" not found.
ERROR: The process "nthlpsvc1.exe" not found.
ERROR: The process "nthlpsvc2.exe" not found.
ERROR: The process "dirlock.exe" not found.
5. Type the following commands or just put it on a BATCH PROGRAM and run it:
for %%i in (C D E F G H I J) do del /f /a %%i:\autorun.inf
DEL /F /A %systemdrive%\Classified.exe
RD /S /Q "%AllUserprofile%\Application Data\Microsoft\Keyboard"
RD /S /Q "%AllUserprofile%\Application Data\PolariSys"
RD /S /Q %Windir%\classified
DEL /F /A "%AllUserprofile%\Desktop\Classified.exe"
DEL /F /A "%AllUserprofile%\Documents\Classified.exe"
DEL /F /A "%AllUserprofile%\Documents\My Music.exe"
DEL /F /A "%AllUserprofile%\Documents\My Pictures.exe"
DEL /F /A "%AllUserprofile%\Documents\My Videos.exe"
DEL /F /A "%AllUserprofile%\Start Menu\Programs\Startup\Classified.exe"
DEL /F /A "%Userprofile%\My Documents\Classified.exe"
DEL /F /A "%Userprofile%\My Documents\My Music.exe"
DEL /F /A "%Userprofile%\My Documents\My Pictures.exe"
DEL /F /A "%systemdrive%Documents and Settings.exe"
DEL /F /A %systemdrive%\Inetpub.exe
DEL /F /A %systemdrive%\goats.exe
DEL /F /A "%ProgramFiles%\Classified.exe"
DEL /F /A "%systemdrive%\Program Files.exe"
DEL /F /A %systemdrive%\Read1st!.exe
DEL /F /A %Windir%\addins\Classified.exe
DEL /F /A %Windir%\addins.exe
DEL /F /A %Windir%\AppPatch\Classified.exe
DEL /F /A %Windir%\AppPatch.exe
DEL /F /A %Windir%\classified\Classified.exe
DEL /F /A %Windir%\Classified.exe
DEL /F /A %Windir%\Config\Classified.exe
DEL /F /A %Windir%\Config.exe
reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /v Sessionmngr /f
reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /v LSAShell /f
reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v WinSys /f
reg add HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer /v NoFolderOptions /f
reg add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore" /v DisableSR /t REG_DWORD /d 1 /f
reg add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" /v Shell /t REG_SZ /d Explorer.exe /f
reg add "HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders" /v AppData /t REG_SZ /d "%WinDir%\system32\config\systemprofile\Application Data" /f
reg add "HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders" /v Cache /t REG_SZ /d "%SystemDrive%\Documents and Settings\LocalService\Local Settings\Temporary Internet Files" /f
reg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN /v CheckedValue /t REG_DWORD /d 2 /f
reg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN /v DefaultValue /t REG_DWORD /d 2 /f
reg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL /v CheckedValue /t REG_DWORD /d 1 /f
reg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL /v DefaultValue /t REG_DWORD /d 2 /f
6. Click START + SEARCH
7. Click All files and folders
8. At the filename box type *.EXE
9. Click More Advance Options.
10. Put a check on the first 3 items and click SEARCH.
11. Kung makakakita po kayo ng mga EXE (Application) na mukang folder, i-delete nyo po.
12. Install an ANTI-VIRUS and UPDATE it then full SCAN your PC then use CCLEANER.
WARNINGS:
- Wag po kay maglalagay ng /F sa taskkill command (step 3).
- Step 12 is optional but very very very important and useful.
- Please don't launch the Task Manager or Registry Editor until you full scan the PC w/ AV.
- Please don't reboot the PC until you full scan the PC w/ AV.
Hope this helps you because this helps me a lot and this is the method i am always using for this trojan/worm.