Shpiel manual removal:
Kill processes:
lovcx.exe, lsass1.exe, msnupdate.exe, saveruser.exe, winbackup.exe, winfog.exe, winlog.exe, winsock.exe, winsress.exe, winsys.exe
Delete registry values:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\hutley-spieluhr
Delete files:lovcx.exe, lsass1.exe, msnupdate.exe, saveruser.exe, winbackup.exe, winfog.exe, winlog.exe, winsock.exe, winsress.exe, winsys.exe
Misc:Shpiel doesn't create all the files listed above, but installs only one of them. This file can be found in default system directory, which is one of the following: C:\Windows\System, c:\Windows\System32, C:\Winnt\System32.
The backdoor uses 25 TCP port.
Post Comment: