Monday, January 19, 2009

Rbot.gen Backdoor

How To Remove Rbot.gen?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
Rbot.gen is dangerous virus:
Backdoors are the most dangerous type of Trojans and the most popular.
Backdoors open infected machines to external control via Internet.
Often the backdoor will not be visible in the log of active programs.


Rbot.gen Symptoms:

Files:
[%COMMON_APPDATA%]\iolo\AntiVirus\Quarantined\protector_update[1].exe.INFECTED
[%SYSTEM%]\dailin.exe
[%SYSTEM%]\lsasss.exe
[%SYSTEM%]\microsoftx.exe
[%SYSTEM%]\nav32sp.exe
[%SYSTEM%]\wowpos32.exe
[%SYSTEM%]\wuamgard.exe
[%SYSTEM%]\wuamgrd.exe
[%SYSTEM%]\xvshost.exe
[%COMMON_APPDATA%]\iolo\AntiVirus\Quarantined\protector_update[1].exe.INFECTED
[%SYSTEM%]\dailin.exe
[%SYSTEM%]\lsasss.exe
[%SYSTEM%]\microsoftx.exe
[%SYSTEM%]\nav32sp.exe
[%SYSTEM%]\wowpos32.exe
[%SYSTEM%]\wuamgard.exe
[%SYSTEM%]\wuamgrd.exe
[%SYSTEM%]\xvshost.exe

Registry Values:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
Remove eShopee Trojan

No comments: