Remove Woredbot.c. Description and removal instructions

 
Title: Woredbot.c

Type: Worms
Severity scale:Woredbot.c severity is 74  (74 / 100)
 
Woredbot.c is a dangerous worm that spreads to network computers by exploiting known vulnerabilities of the Microsoft Windows operating system. It also propagates through network shares and Microsoft SQL servers. Furthermore, the parasite can spread through instant messages using popular clients such as ICQ, AIM, MSN Messenger and Yahoo! Messenger. Once installed, Woredbot.c runs a payload. It disables essential system components and attempts to terminate running firewalls, antiviruses, anti-spyware and anti-malware software. Woredbot.c also opens a back door providing the attacker with unauthorized remote access to the compromised computer. The intruder can download and run arbitrary files, execute any system commands, record user keystrokes, launch Denial of Service (DoS) attacks and search for vulnerable hosts. Furthermore, Woredbot.c can be used to run a hidden proxy service. The parasite is able to steal confidential information the user enters on banking and financial web sites. Woredbot.c runs as a service on every Windows startup.


Related files: mslogon.exe

Woredbot.c properties:
• Allows remote user connection
• Logs keystrokes
• Connects itself to the internet
• Hides from the user
• Stays resident in background

Automatic Woredbot.c removal:

remover for Woredbot.c

Woredbot.c manual removal:

Kill processes:
mslogon.exe
Delete registry values:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Microsoft Logon Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\ENUM\ROOT\LEGACY_MICROSOFT_LOGON_SERVICE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Microsoft Logon Service
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_MICROSOFT_LOGON_SERVICE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\EnableDCOM=n
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Start=4
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Start=4
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\wuauserv\Start=4
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Start=4
Delete files:
mslogon.exe
Misc:
The mslogon.exe file can be found in default system directory, which is one of the following: C:\Windows\System, C:\Windows\System32, C:\Winnt\System32.

Other programs to remove Woredbot.c:

• Malwarebytes Anti Malware - Review - Download
• Malwarebytes Anti Malware - Review - Download
• Windows Defender - Review - Download

Information added: 08/09/06
Information updated: 08/09/06

Additional resources related to Woredbot.c:

Attention: If you know or you have a website or page about Woredbot.c removal, feel free to add a link to this list: add url




more resources

Post Comment:

Attention: Use this form only if you have additional information about Woredbot.c parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.



Enter security code:

Latest spyware news:
Similar parasites: