Remove Kassbot. Description and removal instructions

 
Title: Kassbot
Also known as: Nanspy
Type: Worms
Severity scale:Kassbot severity is 47  (47 / 100)
 
Worm Kassbot, also known as Nanspy, spreads in local area networks. It infects computers running vulnerable Windows version with unpatched security holes. Kassbot modifies essential system settings to block access to certain web sites. It contacts predefined web servers to receive commands from the attacker and download updates. It also compromises other vulnerable network computers. Kassbot is relatively easy to remove. It depends on a single executable located in the default system folder (C:\Windows\System, C:\Windows\System32 or C:\Winnt\System32) and one registry entry.


Kassbot properties:
• Allows remote user connection
• Connects itself to the internet
• Hides from the user
• Stays resident in background

Automatic Kassbot removal:

remover for Kassbot

Kassbot manual removal:

Kill processes:
mmsvc32.exe
Delete registry values:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Microsoft Network Services Controller=%System%\mmsvc32.exe
Delete files:
mmsvc32.exe

Other programs to remove Kassbot:

• Malwarebytes Anti Malware - Review - Download
• Malwarebytes Anti Malware - Review - Download
• Windows Defender - Review - Download

Information added: 26/06/05
Information updated: 26/06/05

Additional resources related to Kassbot:

Attention: If you know or you have a website or page about Kassbot removal, feel free to add a link to this list: add url




more resources

Post Comment:

Attention: Use this form only if you have additional information about Kassbot parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.



Enter security code:

Latest spyware news:
Similar parasites: