Amitis manual removal:
Kill processes:
kernel32.dli
Delete registry values:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\kernel
HKEY_CURRENT_USER\Software\Microsoft\Notepad\showed=yes
HKEY_CLASSES_ROOT\.dli
HKEY_CLASSES_ROOT\dlifile
Delete files:kernel32.dli
Misc:The kernel32.dli file can be found in the default system directory, which is one of the following: C:\Windows\System, C:\Windows\System32 or C:\Winnt\System32.
The backdoor may use different files located in C:\Windows or C:\Winnt folder.
Amitis accepts remote connections on 3547, 7823, 12345, 13173, 44280, 44390, 473870, 64429 TCP ports.
Post Comment: