|
What is Shpiel and removal instructions
Shpiel is a backdoor, which provides the attacker with unauthorized remote access to the compromised computer. Once executed, Shpiel silently installs itself to the system and launches a hidden FTP server, which allows uploading and remote file execution. The intruder can upload arbitrary, potentially malicious files and run them. The backdoor automatically runs on every Windows startup.
Shpiel manual removal: Kill processes: lovcx.exe, lsass1.exe, msnupdate.exe, saveruser.exe, winbackup.exe, winfog.exe, winlog.exe, winsock.exe, winsress.exe, winsys.exe
Delete registry values: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\hutley-spieluhr
Delete files: lovcx.exe, lsass1.exe, msnupdate.exe, saveruser.exe, winbackup.exe, winfog.exe, winlog.exe, winsock.exe, winsress.exe, winsys.exe
Misc: Shpiel doesn't create all the files listed above, but installs only one of them. This file can be found in default system directory, which is one of the following: C:\Windows\System, c:\Windows\System32, C:\Winnt\System32.
The backdoor uses 25 TCP port.
|
|
|
|
|