Remove Wargbot. Description and removal instructions

 
Title: Wargbot

Type: Worms
Severity scale:Wargbot severity is 64  (64 / 100)
 
Wargbot is an Internet worm that spreads by exploiting recent Microsoft Windows vulnerability. The parasite opens a back door providing the attacker with unauthorized remote access to the compromised computer. The intruder can download and run arbitrary files, execute system commands, perform Denial of Service (DoS) attacks, send instant messages and search for vulnerable hosts. Wargbot also turns off the Windows Firewall, disables important system components and modifies some system settings. The worm injects malicious code into the Windows Explorer process in order to avoid detection. Wargbot runs as a service on every Windows startup.


Related files: wgareg.exe

Wargbot properties:
• Allows remote user connection
• Connects itself to the internet
• Hides from the user
• Stays resident in background

Automatic Wargbot removal:

remover for Wargbot

Wargbot manual removal:

Kill processes:
wgareg.exe
Delete registry values:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wgareg
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\EnableDCOM=n
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\EnableFirewall=0
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandarPprofile\EnableFirewall=0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntivirusDisableNotify=1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntivirusOverride=1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify=1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallOverride=1
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\restrictanonymous=1
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\restrictanonymousaam=1
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lanmanserver\Parameters\autoshareserver=0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lanmanserver\Parameters\autosharewks=0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Start=4
Delete files:
wgareg.exe
Misc:
The wgareg.exe file can be found in the default system directory, which is one of the following: C:\Windows\System, C:\Windows\System32, C:\Winnt\System32.

Other programs to remove Wargbot:

• Malwarebytes Anti Malware - Review - Download
• Malwarebytes Anti Malware - Review - Download
• Windows Defender - Review - Download

Information added: 14/08/06
Information updated: 14/08/06

Additional resources related to Wargbot:

Attention: If you know or you have a website or page about Wargbot removal, feel free to add a link to this list: add url




more resources

Post Comment:

Attention: Use this form only if you have additional information about Wargbot parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.



Enter security code:

Latest spyware news:
Similar parasites: