The process Reader_sl.exe:1064 makes changes in a system registry. The PUP creates and/or sets the following values in system registry: [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}] Page 1 of 2 - Possible victim of Bitcoin Botnet - posted in Virus, Trojan, Spyware, and Malware Removal Help: As instructed, I created a new forum topic and am following the Preparation Guide. DDS Hi guys. I recently started to notice that whenever I play a game, any game, I get a smooth 120 fps but then after a couple of minutes it drops to about 20 to 10 fps. I found out after some time what the problem was. When I opened task manager I could see that 2 processes are using like 90% of my... It seemed to be running a process called 'jsheded.exe' located in the Java update folder. I looked up this process and saw it was malicious (the normal Java update process is called 'jusched.exe'). I disabled it in msconfig and it kept re-enabling itself, and then stopped after a few days (whew). TeslaCrypt is a well-known ransomware family that encrypts a user's files with strong encryption and demands Bitcoin in exchange for a file decryption service. A flaw in the encryption algorithm was discovered that allowed files to be decrypted without paying the ransomware, and eventually, the malware developers released the master key

