From a hidden group
Analysis Tool: Sandbox Trojan helper Finder
Rogue behavior:
No uninstall Method
The IE shortcut generated is directed to a webpage and cannot be deleted. It still appears after force deletion and restart
Use the optimization master to uninstall and restart and restore
Unknown process nlce. nls mactool.exe constantly changes the pid. Dual-process cross-protection technology, which is a trojan feature.
Uninstall method:
1. uninstall it once with the optimization master. The software installation directory is CProgram Filesprocedure.
2. Delete the following items:
System32 folder
Halgdsl. skv msvcp71.dll msvcr71.dll tasxelv.exe files
The current application DataMac under the user name generates the mac. key macjie. key soft. ini file.
Application DataMicrosoftAddInsgcmcy. dll
Application DataMicrosoftInternet assumerquick Launch generates an IE shortcut to directly connect to their home page
Application DataMicrosoftMMC generates ycmcg. dll
These files in the Application Data folder are the key to restarting the malware and are not deleted.
Conclusion: 1. Uninstall with Master Optimization Analysis
2 search on drive C
Halgdsl. skv msvcp71.dll msvcr71.dll tasxelv.exe mac. key macjie. key gcmcy. dll ycmcg. dll
Back up and then delete
3. Under the user name, the IE shortcut is generated in Application DataMicrosoftInternet assumerquick Launch and deleted.
4. Remove unnecessary IE Shortcuts Using the unused shortcut cleanup tools provided by the system