Title: Litmus
Type: Backdoors

Remove Litmus. Removal instructions


 
Severity scale:Litmus severity is 72  (72 / 100)
 
Litmus is a dangerous backdoor that gives the attacker remote unauthorized access to a compromised computer. The parasite is controlled through IRC chat network. It allows the intruder to manage files, download and execute arbitrary files, reconfigure backdoor settings and steal system and network information. Litmus also attempts to collect user login names, various passwords and other confidential data. The parasite secretly runs on every Windows startup.

Litmus properties:
• Allows remote user connection
• Connects itself to the internet
• Hides from the user
• Stays resident in background

Automatic Litmus removal:

SpyHunter is recommended remover to uninstall Litmus. You should confirm using free trial that it detects current version of parasite.

Note: Manual assistance required means that one or all of removers were unable to remove parasite without some manual intervention, please read manul removal instructions below.

If you failed to remove Litmus using SpyHunter please report this to us.

We might be affiliated with any product we recommend on the site. Full disclosure in our Agreement of Use.
STOPzilla
We are testing STOPzilla's efficiency at removing Litmus (2005-09-27 16:56:34)
Malwarebytes Anti Malware
We are testing Malwarebytes Anti Malware's efficiency at removing Litmus (2005-09-27 16:56:34)
Spyware Doctor
We are testing Spyware Doctor's efficiency at removing Litmus (2005-09-27 16:56:34)
XoftSpySE Anti Spyware

Litmus manual removal:

Kill processes:
blah.exe, erm.exe, image32.exe, mgdoll.exe, mm.exe, msgsrv16.exe, svchost.exe, winsys.exe
Delete registry values:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\LTM2
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\WIN2
Delete files:
blah.exe, erm.exe, image32.exe, mgdoll.exe, mm.exe, msgsrv16.exe, svchost.exe, winsys.exe
Delete directories:
C:\Windows\Appsvc
C:\Winnt\Appsvc
C:\Windows\img32b
C:\Winnt\img32b
C:\Windows\Litmus
C:\Winnt\Litmus
C:\Windows\Random
C:\Winnt\Random
C:\Windows\Winsys
C:\Winnt\Winsys
Misc:
Exact file location:
blah.exe - C:\Windows\VxD or C:\Winnt\VxD
erm.exe, mm.exe, mgdoll.exe msgsrv16.exe - C:\Windows\Litmus or C:\Winnt\Litmus
image32.exe - C:\Windows\img32b or C:\Winnt\img32b
svchost.exe - C:\Windows\Random, C:\Winnt\Random or C:\Windows\Appsvc, C:\Winnt\Appsvc
winsys.exe - C:\Windows\Winsys or C:\Winnt\Winsys
Information added: 2004-03-19 10:00:00
Information updated: 2005-09-27 14:19:19

Additional resources related to Litmus:

Attention: If you know or you have a website or page about Litmus removal, feel free to add a link to this list: add url

more resources

Post Comment:

Attention: Use this form only if you have additional information about Litmus parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.
Home page Name



«


* All field required
Latest spyware news:
Subscribe to news

Similar parasites:
Related discussions:
Compare spyware removers
Compare free products

HijackThis Log Analyzer Beta 2 HijackThis Log Analyzer Beta 2

I failed to remove Litmus using SpyHunter.

Email


Close

Spreading the knowledge:

It is very hard to fight Computer parasites alone in internet space. If you have a website we would be more than happy if you would help us to spread the knowledge about latest threats. You can help your visitors to manage their Computer system manually without aditional expences. Knowledge is the power, we just need to spread it.
add text box
rss feed
help other