Remove Fanbot. Description and removal instructions

 
Title: Fanbot

Type: Worms
Severity scale:Fanbot severity is 85  (85 / 100)
 
Fanbot is an extremely dangerous rapidly spreading Internet worm that propagates by e-mail, through file sharing networks and exploiting known Microsoft Windows vulnerabilities.

Once executed, the parasite displays a fake error message, runs its payload and initiates a spreading routine. The worm usually arrives in e-mail messages with archived attachments containing infected files. Fanbot letters have fake "From" address field and therefore look like being sent by the local administrator, webmaster, support or information service. The worm uses own mail engine to distribute such messages. It also creates infected files with various meaningful names and copies them into shared folders of most popular peer-to-peer applications and instant messengers.

The parasite's payload is comprised of several malicious functions. Fanbot runs an integrated backdoor that gives the attacker unauthorized remote access to a compromised computer. The intruder can manage the file system, run and terminate programs, execute local commands, download and upload arbitrary files, access specified web resources, control the worm, perform annoying actions, shutdown or restart a computer, attack defined hosts, etc. The parasite itself attempts to kill active processes related to installed antiviruses, firewalls and security-related software. It also blocks access to popular security-related web sites and disables certain Windows components.

Fanbot secretly runs as a service on every system startup.


Fanbot properties:
• Allows remote user connection
• Sends out logs by FTP or email
• Connects itself to the internet
• Hides from the user
• Stays resident in background

Automatic Fanbot removal:

remover for Fanbot

Fanbot manual removal:

Kill processes:
remote.exe
Delete registry values:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RpcRemotes
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Start=4
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Start=4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\Ph4nt0m
Delete files:
remote.exe
Misc:
The remote.exe file can be found in default system directory, which is one of the following: C:\Windows\System, C:\Windows\System32, C:\Winnt\System32.

Other programs to remove Fanbot:

• SUPERAntiSpyware - Review - Download
• CounterSpy - Review - Download
• Windows Defender - Review - Download

Information added: 18/10/05
Information updated: 18/10/05

Additional resources related to Fanbot:

Attention: If you know or you have a website or page about Fanbot removal, feel free to add a link to this list: add url




more resources

Post Comment:

Attention: Use this form only if you have additional information about Fanbot parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.



Enter security code:

Latest spyware news:
Similar parasites: