Remove Loxbot.b. Description and removal instructions

 
Title: Loxbot.b

Type: Worms
Severity scale:Loxbot.b severity is 79  (79 / 100)
 
Loxbot.b is a dangerous Internet worm, which propagates through unprotected network shares with weak passwords and uses AOL Instant Messenger to spread through messages containing malicious links that silently download and install the parasite. Once executed, Loxbot.b runs its payload and spreading routine. The worm activates an integrated backdoor controlled through the IRC network, which gives the attacker unauthorized remote access to a compromised computer. It allows the intruder to download and execute arbitrary files, steal user passwords, scan the local network, launch a Denial of Service attack, update the worm and perform other dangerous actions. Loxbot.b automatically runs on every Windows startup.


Loxbot.b properties:
• Allows remote user connection
• Connects itself to the internet
• Hides from the user
• Stays resident in background

Automatic Loxbot.b removal:

remover for Loxbot.b

Loxbot.b manual removal:

Kill processes:
express.exe
Delete registry values:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Outlook Mail Service=express.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Outlook Mail Service=express.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\Outlook Mail Service=express.exe
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\EnableFirewall=0
Delete files:
express.exe
Misc:
The express.exe file is located in default system directory, which is one of the following: C:\Windows\System, C:\Windows\System32, C:\Winnt\System32.

Loxbot.b uses 9515 TCP port.

Other programs to remove Loxbot.b:

• SUPERAntiSpyware - Review - Download
• CounterSpy - Review - Download
• Windows Defender - Review - Download

Information added: 01/11/05
Information updated: 01/11/05

Additional resources related to Loxbot.b:

Attention: If you know or you have a website or page about Loxbot.b removal, feel free to add a link to this list: add url




more resources

Post Comment:

Attention: Use this form only if you have additional information about Loxbot.b parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.



Enter security code:

Related news:
Similar parasites: