Remove Botter. Description and removal instructions

 
Title: Botter

Type: Worms
Severity scale:Botter severity is 69  (69 / 100)
 
Botter is a dangerous rapidly spreading Internet worm that propagates by e-mail and through IRC online chat network. The parasite arrives in RAR archives containing malicious files.

Once executed, Botter silently installs itself to the system, runs a payload and spreading routine. The worm sends e-mail messages with attached archives containing infected executables to all the contacts in Windows Address Book. It connects to predetermined IRC servers, joins certain channels and sends private messages to other users. These messages contain a link that downloads an infected file from a web server that the worm runs on a compromised computer. Botter can also directly send malicious files to chat users through specific DCC commands.

The parasite's payload is comprised of several harmful functions. Botter searches all fixed, removable and remote drives for RAR archives and inserts a randomly named copy of itself in all archives found. It installs a variant of Spybot worm, which gives the attacker unauthorized remote access to a compromised computer, terminates practically all known antiviruses, firewalls and security-related programs and blocks access to popular security-related web sites and services. Botter also disables certain Windows components.

The worm automatically runs on every Windows startup.



Botter properties:
• Connects itself to the internet
• Hides from the user
• Stays resident in background

Automatic Botter removal:

remover for Botter

Botter manual removal:

Kill processes:
tasksys.exe, local.exe
Delete registry values:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Windows Task Service (32-bits)
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Start=4
Delete files:
tasksys.exe, local.exe
Misc:
Botter e-mail attachments and distributed files have varying names.

Exact file location:
local.exe - C:
tasksys.exe - C:\Windows\System, C:\Windows\System32 or C:\Winnt\System32

Other programs to remove Botter:

• SUPERAntiSpyware - Review - Download
• CounterSpy - Review - Download
• Windows Defender - Review - Download

Information added: 21/10/05
Information updated: 21/10/05

Additional resources related to Botter:

Attention: If you know or you have a website or page about Botter removal, feel free to add a link to this list: add url




more resources

Post Comment:

Attention: Use this form only if you have additional information about Botter parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.



Enter security code:

Latest spyware news:
Similar parasites:
Related discussions: