Home > Security > Spyware
Search:
Remove W32.IRCBot.B
Hits:67

What is W32.IRCBot.B and removal instructions

W32.IRCBot.B is a Backdoor Trojan Horse that connects to an IRC server and waits for commands from the hacker. This Trojan is a variant of W32.IRCBot and W32.IRCBot.Gen.
The Trojan may arrive in an email which looks like this:
From: updates@symantec.com (spoofed email address)
Subject: Last Update.
Attachment: nav32.zip
Attachment Type: Zip file
Attachment Size: 15.5 Kbytes

W32.IRCBot.B manual removal:
Kill processes:
updt.exe
Delete registry values:
Browse to the key:
'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
Delete the value ''windowsupdate'='%SYSTEM%\RPC.exe''
Browse to the key:
'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ RunServices'
Delete the value 'windowsupdate'='%SYSTEM%\RPC.exe'
Delete files:
updt.exe

Home | About Us | Privacy Policy
Copyright 2007-2017 RegistryWinner.com. All rights reserved.