Remove Mubla. Description and removal instructions

 
Title: Mubla

Type: Worms
Severity scale:Mubla severity is 53  (53 / 100)
 
Mubla is a worm that spreads through instant messages using the MSN Messenger program. Once executed, the parasite secretly installs itself to the system. Then it runs a payload. Mubla starts to act as a botnet client. It connects to its control server and awaits commands from the attacker. The intruder can download arbitrary files and steal user passwords. The worm runs on every Windows startup.


Related files: syshosts.dll, photos.zip

Mubla properties:
• Allows remote user connection
• Connects itself to the internet
• Hides from the user
• Stays resident in background

Automatic Mubla removal:

remover for Mubla

Mubla manual removal:

Delete registry values:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\syshosts
HKEY_CLASSES_ROOT\CLSID\{063D385B-25DB-41C3-80C3-6ADC5DE65B2E}
Unregister DLLs:
syshosts.dll

Delete files:
syshosts.dll, photos.zip
Misc:
Exact file location:
photos.zip - C:\WINDOWS or C:\WINNT
syshosts.dll - C:\WINDOWS\System32 or C:\WINNT\System32

Other programs to remove Mubla:

• SUPERAntiSpyware - Review - Download
• CounterSpy - Review - Download
• Windows Defender - Review - Download

Information added: 01/06/07
Information updated: 18/09/07

Additional resources related to Mubla:

Attention: If you know or you have a website or page about Mubla removal, feel free to add a link to this list: add url




more resources

Post Comment:

Attention: Use this form only if you have additional information about Mubla parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.



Enter security code:

Latest spyware news:
Similar parasites: