Title: GiftCom
Type: Worms

Remove GiftCom. Removal instructions


 
Severity scale:GiftCom severity is 75  (75 / 100)
 
GiftCom is an Internet worm that spreads to other computers through unpatched security vulnerabilities and via instant messages using popular chat programs including ICQ, AIM, MSN Messenger and Yahoo! Messenger. The parasite sends bogus messages containing links to malicious files to all the contacts in the victim's buddy list. Once the user follows such a link, GiftCom is silently downloaded and installed to the system. The worm comes with a rootkit that hides all harmful processes and files from most antivirus tools. The GiftCom's payload is comprised of several malicious functions. First of all, the worm disables some Windows essential components and terminates running antiviruses and security-related programs. Then it runs a backdoor component, which provides the attacker with unauthorized remote access to the compromised computer. The intruder can log user keystrokes, set up a hidden FTP server, intercept network and Internet traffic, contact specified web resources and steal user sensitive information. GiftCom can also change the web browser's default home page and download a variant of the Sdbot worm. The threat automatically runs as a service on every Windows startup.

GiftCom properties:
• Allows remote user connection
• Logs keystrokes
• Changes browser settings
• Connects itself to the internet
• Hides from the user
• Stays resident in background

Automatic GiftCom removal:

SpyHunter is recommended remover to uninstall GiftCom. You should confirm using free trial that it detects current version of parasite.

Note: Manual assistance required means that one or all of removers were unable to remove parasite without some manual intervention, please read manul removal instructions below.

If you failed to remove GiftCom using SpyHunter please report this to us.

We might be affiliated with any product we recommend on the site. Full disclosure in our Agreement of Use.
STOPzilla
We are testing STOPzilla's efficiency at removing GiftCom (2005-12-26 08:51:36)
Malwarebytes Anti Malware
We are testing Malwarebytes Anti Malware's efficiency at removing GiftCom (2005-12-26 08:51:36)
Spyware Doctor
We are testing Spyware Doctor's efficiency at removing GiftCom (2005-12-26 08:51:36)
XoftSpySE Anti Spyware

GiftCom manual removal:

Kill processes:
winrpc.exe
Delete registry values:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\winrpc
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Messenger\Start=4
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\Start=4
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr\Start=4
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\RestrictAnonymous=1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\EnableDCOM=n
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\DoNotAllowXPSP2=1
Delete files:
winrpc.exe
Misc:
The winrpc.exe file can be found in main Windows folder, which is usually C:\Windows or C:\Winnt.
Information added: 2005-12-26 06:14:21
Information updated: 2005-12-26 06:14:21

Additional resources related to GiftCom:

Attention: If you know or you have a website or page about GiftCom removal, feel free to add a link to this list: add url

more resources

Post Comment:

Attention: Use this form only if you have additional information about GiftCom parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.
Home page Name



«


* All field required
Related news:
Similar parasites:
Compare spyware removers
Compare free products

HijackThis Log Analyzer Beta 2 HijackThis Log Analyzer Beta 2

I failed to remove GiftCom using SpyHunter.

Email


Close

Spreading the knowledge:

It is very hard to fight Computer parasites alone in internet space. If you have a website we would be more than happy if you would help us to spread the knowledge about latest threats. You can help your visitors to manage their Computer system manually without aditional expences. Knowledge is the power, we just need to spread it.
add text box
rss feed
help other