W32/Randex-Y

Category: Viruses and Spyware Protection available since:11 Jan 2004 00:00:00 (GMT)
Type: Win32 worm Last Updated:11 Jan 2004 00:00:00 (GMT)
Prevalence: Small Number of Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

Aliases

  • WORM_RANDEX.GEN
  • Backdoor.IRCBot.gen

Affected Operating Systems

Windows

Recovery Instructions:

Please follow the instructions for removing worms.

Delete the file remove.bat in the Windows temp folder if it exists.

Check your administrator passwords and review network security.

You will also need to edit the following registry entries, if they are present. Please read the warning about editing the registry.

At the taskbar, click Start|Run. Type 'Regedit' and press Return. The registry editor opens.

Before you edit the registry, you should make a backup. On the 'Registry' menu, click 'Export Registry File'. In the 'Export range' panel, click 'All', then save your registry as Backup.

Locate the HKEY_LOCAL_MACHINE entries:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\IRBMe Sucks!!
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\IRBMe Sucks!!

and delete them if they exist.

Close the registry editor.

download Try Sophos products for free
Download now