Remove Busboy. Description and removal instructions

 
Title: Busboy

Type: Worms
Severity scale:Busboy severity is 57  (57 / 100)
 
Busboy is a worm that spreads through removable media and mapped network drives. Once executed, the parasite secretly installs itself to the system and runs a payload. It logs keystrokes in attempt to steal user sensitive information. Gathered data can be transferred to a remote server. Busboy runs on every Windows startup.


Related files: svchost.exe, boothide.reg, bootrun.reg

Busboy properties:
• Logs keystrokes
• Connects itself to the internet
• Hides from the user
• Stays resident in background

Automatic Busboy removal:

remover for Busboy

Busboy manual removal:

Kill processes:
svchost.exe
Delete registry values:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit=userinit.exe,%System%\scvhost\svchost.exe,wuauserv.exe
Delete files:
svchost.exe, boothide.reg, bootrun.reg
Delete directories:
C:\WINDOWS\System32\scvhost
C:\WINNT\System32\scvhost
Misc:
Exact file location:
boothide.reg, bootrun.reg - C:\WINDOWS\System32 or C:\wINNT\System32
svchost.exe - C:\WINDOWS\System32\scvhost or C:\WINNT\System32\scvhost

Other programs to remove Busboy:

• SUPERAntiSpyware - Review - Download
• CounterSpy - Review - Download
• Windows Defender - Review - Download

Information added: 04/01/07
Information updated: 04/01/07

Additional resources related to Busboy:

Attention: If you know or you have a website or page about Busboy removal, feel free to add a link to this list: add url




more resources

Post Comment:

Attention: Use this form only if you have additional information about Busboy parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.



Enter security code:

Latest spyware news:
Similar parasites: