|
What is Ezibot and removal instructions
Ezibot is a backdoor that provides the attacker with unauthorized remote access to the compromised computer. The intruder can download and execute arbitrary files, record keystrokes, steal user sensitive information, update the backdoor and shutdown the computer. Ezibot secretly runs on every Windows startup.
Ezibot manual removal: Kill processes: svchos.exe, svchos-upd.exe
Delete registry values: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\svchos
HKEY_LOCAL_MACHINE\SOFTWARE\Ezhik
Delete files: svchos.exe, svchos-upd.exe, svchos29.dll
Misc: Ezibot files reside in the main Windows folder C:\Windows or C:\Winnt.
|
|
|
|
|