Amitis.c manual removal:
Kill processes:
almv.exe, dlmvd.exe, dlmvp.exe, dlmvt.exe, dlmvx.exe, mvh.exe, mvs.exe, rcs.exe
Delete registry values:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ALMV
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell=explorer.exe %Windir%\mvh.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit=userinit.exe %Windir%\mvh.exe
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\Load=%Windir%\mvs.exe
Delete files:almv.exe, dlmvd.exe, dlmvp.exe, dlmvt.exe, dlmvx.exe, mvh.exe, mvs.exe, rcs.exe, rtemp.bat, rtmp.bat, rtmp.scr, msinsck.ocx
Misc:Amitis.c uses TCP port 3891.
Exact file location:
mvh.exe, mvs.exe - C:\WINDOWS or C:\WINNT
almv.exe, dlmvd.exe, dlmvp.exe, dlmvt.exe, dlmvx.exe, rcs.exe, rtemp.bat, rtmp.bat, rtmp.scr, msinsck.ocx - C:\WINDOWS\System32 or C:\WINNT\System32
Post Comment: